Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to an Out-of-bounds Write error when assigning ESI variables, Squid is susceptible to a Memory Corruption error. This error can lead to a Denial of Service attack.
CVSS Details
- CVSS 3.1 Base Score: 6.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade squid | Jul 29, 2024 | Jun 25, 2024 |
| Amazon Linux Ami 2 | — | Upgrade squidUpgrade squid-debuginfoUpgrade squid-sysvinitUpgrade squid-migration-script | Aug 14, 2024 | Jun 25, 2024 |
| Amazon_linux_2023 | — | Upgrade squid-debuginfoUpgrade squid-debugsourceUpgrade squid | Feb 17, 2025 | Jun 25, 2024 |
| Debian | — | Upgrade squid | Aug 21, 2024 | Jun 25, 2024 |
| Oracle_linux | — | Upgrade squid | Aug 16, 2024 | Jun 25, 2024 |
| Redhat_linux | — | Upgrade squidNo solution existsUpgrade squid-debuginfoUpgrade squid-debugsource | Jul 26, 2024 | Jun 25, 2024 |
| Rocky_linux | — | Upgrade squidUpgrade squid-debuginfoUpgrade squid-debugsource | Jul 29, 2024 | Jun 25, 2024 |
| Suse | — | Upgrade squid | Jul 3, 2024 | Jun 25, 2024 |
| Ubuntu | — | Upgrade squid3 (Ubuntu Pro)Upgrade squid (Ubuntu Pro)Upgrade squid | Jul 24, 2024 | Jun 25, 2024 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jun 25, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub