The Squid Software Foundation Squid HTTP Caching Proxy version 3.0 to 3.5.27, 4.0 to 4.0.22 contains a Incorrect Pointer Handling vulnerability in ESI Response Processing that can result in Denial of Service for all clients using the proxy.. This attack appear to be exploitable via Remote server delivers an HTTP response payload containing valid but unusual ESI syntax.. This vulnerability appears to have been fixed in 4.0.23 and later.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade squid | Mar 6, 2018 | Feb 9, 2018 |
| Amazon_linux | — | Upgrade squid | Sep 20, 2018 | Feb 9, 2018 |
| Centos_linux | — | Upgrade squidUpgrade squid-migration-scriptUpgrade squid-sysvinitUpgrade squid-debuginfo | Apr 1, 2020 | Feb 9, 2018 |
| Debian | — | Upgrade squidUpgrade squid3 | Feb 24, 2018 | Feb 9, 2018 |
| Freebsd | — | Upgrade squid-develUpgrade squid | Feb 24, 2018 | Feb 23, 2018 |
| Huawei Euleros 2_0_sp1 | — | Upgrade squidUpgrade squid-migration-script | May 2, 2018 | Feb 9, 2018 |
| Huawei Euleros 2_0_sp2 | — | Upgrade squidUpgrade squid-migration-script | May 2, 2018 | Feb 9, 2018 |
| Oracle Solaris | — | Upgrade entire/ to version 11.4-11.4.0.0.1.15.0 on Solaris 11.4 | Oct 19, 2018 | Feb 9, 2018 |
| Oracle_linux | — | Upgrade squidUpgrade squid-sysvinitUpgrade squid-migration-script | Oct 5, 2022 | Jan 19, 2018 |
| Redhat_linux | — | Upgrade squid-sysvinitNo solution existsUpgrade squid-debuginfoUpgrade squid-migration-scriptUpgrade squid | Apr 1, 2020 | Feb 9, 2018 |
| Suse | — | Upgrade squidUpgrade squid3 | Mar 10, 2018 | Feb 9, 2018 |
| Ubuntu | — | Upgrade squid3 | Apr 25, 2018 | Feb 9, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub