CVE-2024-37894: Squid vulnerable to heap corruption in ESI assign
Last updated 25 July 2024
Other sources
Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to an Out-of-bounds Write error when assigning ESI variables, Squid is susceptible to a Memory Corruption error. This error can lead to a Denial of Service attack.
— NVD
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37894?
CVE-2024-37894 has a high severity rating due to the potential for memory corruption leading to Denial of Service attacks.
How do I fix CVE-2024-37894?
To fix CVE-2024-37894, upgrade Squid to version 5.7-2+deb12u2 or 6.10-1 if you are using a version that is affected.
What versions of Squid are affected by CVE-2024-37894?
CVE-2024-37894 affects Squid versions up to inclusive 4.13-10+deb11u3.
What type of attack can CVE-2024-37894 lead to?
CVE-2024-37894 can lead to Denial of Service attacks due to a memory corruption error.
Is there any workaround for CVE-2024-37894?
There are no known workarounds for CVE-2024-37894, so upgrading is essential for security.