Squid is an open source caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to Input Validation, Premature Release of Resource During Expected Lifetime, and Missing Release of Resource after Effective Lifetime bugs, Squid is vulnerable to Denial of Service attacks by a trusted server against all clients using the proxy. This bug is fixed in the default build configuration of Squid version 6.10.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade squidUpgrade libecap-develUpgrade libecap | Nov 18, 2024 | Oct 28, 2024 |
| Amazon_linux_2023 | — | Upgrade squidUpgrade squid-debuginfoUpgrade squid-debugsource | Feb 26, 2025 | Oct 28, 2024 |
| Debian | — | Upgrade squid | Mar 13, 2025 | Oct 28, 2024 |
| Oracle_linux | — | Upgrade squid-migration-scriptUpgrade libecap-develUpgrade squidUpgrade squid-sysvinitUpgrade libecap | Nov 21, 2024 | Oct 28, 2024 |
| Redhat_linux | — | Upgrade libecap-debuginfoUpgrade squid-debuginfoUpgrade libecap-debugsourceUpgrade squid-debugsourceUpgrade squidUpgrade libecap-develUpgrade squid-migration-scriptNo solution existsUpgrade squid-sysvinitUpgrade libecap | Nov 27, 2024 | Oct 28, 2024 |
| Rocky_linux | — | Upgrade squid-debugsourceUpgrade squid-debuginfoUpgrade libecapUpgrade libecap-debuginfoUpgrade libecap-debugsourceUpgrade squidUpgrade libecap-devel | Nov 20, 2024 | Oct 28, 2024 |
| Suse | — | Upgrade squid | Dec 5, 2025 | Oct 28, 2024 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Oct 28, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub