Squid is an open source caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to Input Validation, Premature Release of Resource During Expected Lifetime, and Missing Release of Resource after Effective Lifetime bugs, Squid is vulnerable to Denial of Service attacks by a trusted server against all clients using the proxy. This bug is fixed in the default build configuration of Squid version 6.10.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | alma-upgrade-libecapalma-upgrade-libecap-develalma-upgrade-squid | Nov 18, 2024 | Oct 28, 2024 | |
| Amazon_linux_2023 | amazon-linux-2023-upgrade-squidamazon-linux-2023-upgrade-squid-debuginfoamazon-linux-2023-upgrade-squid-debugsource | Feb 26, 2025 | Oct 28, 2024 | |
| Debian | debian-upgrade-squid | Mar 13, 2025 | Oct 28, 2024 | |
| Oracle_linux | oracle-linux-upgrade-libecaporacle-linux-upgrade-libecap-develoracle-linux-upgrade-squidoracle-linux-upgrade-squid-migration-scriptoracle-linux-upgrade-squid-sysvinit | Nov 21, 2024 | Oct 28, 2024 | |
| Redhat_linux | redhat-upgrade-libecapredhat-upgrade-libecap-debuginforedhat-upgrade-libecap-debugsourceredhat-upgrade-libecap-develredhat-upgrade-squidredhat-upgrade-squid-debuginforedhat-upgrade-squid-debugsourceredhat-upgrade-squid-migration-scriptredhat-upgrade-squid-sysvinit | Nov 27, 2024 | Oct 28, 2024 | |
| Rocky_linux | rocky-upgrade-libecaprocky-upgrade-libecap-debuginforocky-upgrade-libecap-debugsourcerocky-upgrade-libecap-develrocky-upgrade-squidrocky-upgrade-squid-debuginforocky-upgrade-squid-debugsource | Nov 20, 2024 | Oct 28, 2024 | |
| Suse | — | suse-upgrade-squid | Dec 5, 2025 | Oct 28, 2024 |
| Vmware Photon_os | vmware-photon_os_update_tdnf | Jan 20, 2025 | Oct 28, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub