A flaw was found in Squid. The limits applied for validation of HTTP response headers are applied before caching. However, Squid may grow a cached HTTP response header beyond the configured maximum size, causing a stall or crash of the worker process when a large header is retrieved from the disk cache, resulting in a denial of service.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade squidUpgrade libecap-develUpgrade libecap | Nov 24, 2023 | Nov 3, 2023 |
| Alpine Linux | — | Upgrade squid | Mar 21, 2024 | Nov 3, 2023 |
| Amazon_linux_2023 | — | Upgrade squid-debugsourceUpgrade squid-debuginfoUpgrade squid | Feb 17, 2025 | Oct 19, 2023 |
| Centos_linux | — | Upgrade squidUpgrade libecap-develUpgrade squid-debuginfoUpgrade squid-debugsourceUpgrade libecapUpgrade libecap-debuginfoUpgrade libecap-debugsource | Nov 23, 2023 | Nov 3, 2023 |
| Debian | — | Upgrade squid | May 15, 2025 | Nov 3, 2023 |
| Oracle_linux | — | Upgrade libecapUpgrade squidUpgrade libecap-devel | Nov 28, 2023 | Oct 19, 2023 |
| Redhat_linux | — | Upgrade squid-debuginfoUpgrade libecap-debugsourceUpgrade squid-debugsourceNo solution existsUpgrade squidUpgrade libecapUpgrade libecap-develUpgrade libecap-debuginfo | Nov 23, 2023 | Nov 3, 2023 |
| Rocky_linux | — | Upgrade libecap-debuginfoUpgrade libecapUpgrade libecap-debugsourceUpgrade libecap-devel | Aug 15, 2024 | Nov 3, 2023 |
| Ubuntu | — | Upgrade squid | Apr 11, 2024 | Nov 3, 2023 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Nov 3, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub