An issue was discovered in Squid through 4.7. When Squid is parsing ESI, it keeps the ESI elements in ESIContext. ESIContext contains a buffer for holding a stack of ESIElements. When a new ESIElement is parsed, it is added via addStackElement. addStackElement has a check for the number of elements in this buffer, but it's off by 1, leading to a Heap Overflow of 1 element. The overflow is within the same structure so it can't affect adjacent memory blocks, and thus just leads to a crash while processing.
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | alma-upgrade-libecapalma-upgrade-libecap-devel | May 4, 2022 | Apr 15, 2020 | |
| Alpine Linux | alpine-linux-upgrade-squid | Jan 5, 2021 | Apr 15, 2020 | |
| Amazon Linux Ami 2 | amazon-linux-ami-2-upgrade-squidamazon-linux-ami-2-upgrade-squid-debuginfoamazon-linux-ami-2-upgrade-squid-migration-scriptamazon-linux-ami-2-upgrade-squid-sysvinit | Sep 28, 2023 | Apr 15, 2020 | |
| Amazon_linux | — | amazon-linux-upgrade-squid | Jun 4, 2020 | Apr 15, 2020 |
| Centos_linux | — | centos-upgrade-libecapcentos-upgrade-libecap-debuginfocentos-upgrade-libecap-debugsourcecentos-upgrade-libecap-develcentos-upgrade-squidcentos-upgrade-squid-debuginfocentos-upgrade-squid-debugsource | Nov 5, 2020 | Apr 15, 2020 |
| Debian | debian-upgrade-squid | May 11, 2020 | Apr 15, 2020 | |
| Gentoo Linux | gentoo-linux-upgrade-net-proxy-squid | Jun 15, 2020 | Apr 15, 2020 | |
| Huawei Euleros 2_0_sp2 | huawei-euleros-2_0_sp2-upgrade-squidhuawei-euleros-2_0_sp2-upgrade-squid-migration-script | Jun 17, 2020 | Apr 15, 2020 | |
| Huawei Euleros 2_0_sp3 | huawei-euleros-2_0_sp3-upgrade-squidhuawei-euleros-2_0_sp3-upgrade-squid-migration-script | Sep 28, 2020 | Apr 15, 2020 | |
| Huawei Euleros 2_0_sp5 | huawei-euleros-2_0_sp5-upgrade-squid | Sep 3, 2020 | Apr 15, 2020 | |
| Huawei Euleros 2_0_sp8 | huawei-euleros-2_0_sp8-upgrade-squid | Jul 31, 2020 | Apr 15, 2020 | |
| Oracle Solaris | oracle-solaris-11-4-upgrade-web-proxy-squid-4-11-11-4-22-0-1-69-4 | Jan 19, 2021 | Apr 15, 2020 | |
| Oracle_linux | — | oracle-linux-upgrade-libecaporacle-linux-upgrade-libecap-develoracle-linux-upgrade-squid | Jul 22, 2024 | Apr 24, 2020 |
| Redhat_linux | no-fix-redhat-rpm-packageredhat-upgrade-libecapredhat-upgrade-libecap-debuginforedhat-upgrade-libecap-debugsourceredhat-upgrade-libecap-develredhat-upgrade-squidredhat-upgrade-squid-debuginforedhat-upgrade-squid-debugsource | Nov 5, 2020 | Apr 15, 2020 | |
| Rocky_linux | rocky-upgrade-libecaprocky-upgrade-libecap-debuginforocky-upgrade-libecap-debugsourcerocky-upgrade-libecap-devel | Mar 12, 2024 | Apr 15, 2020 | |
| Suse | — | suse-upgrade-squidsuse-upgrade-squid3 | Apr 30, 2020 | Apr 15, 2020 |
| Ubuntu | ubuntu-upgrade-squid | Jun 24, 2020 | Apr 15, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub