First published: Wed Jun 26 2024(Updated: )
Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to an Out-of-bounds Write error when assigning ESI variables, Squid is susceptible to a Memory Corruption error. This error can lead to a Denial of Service attack. References: <a href="https://github.com/squid-cache/squid/security/advisories/GHSA-wgvf-q977-9xjg">https://github.com/squid-cache/squid/security/advisories/GHSA-wgvf-q977-9xjg</a> <a href="https://megamansec.github.io/Squid-Security-Audit/esi-underflow.html">https://megamansec.github.io/Squid-Security-Audit/esi-underflow.html</a> Upstream patch: <a href="https://github.com/squid-cache/squid/commit/f411fe7d75197852f0e5ee85027a06d58dd8df4c.patch">https://github.com/squid-cache/squid/commit/f411fe7d75197852f0e5ee85027a06d58dd8df4c.patch</a>
Affected Software | Affected Version | How to fix |
---|---|---|
Squid Web Proxy Cache |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.