Description
Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to an Out-of-bounds Write error when assigning ESI variables, Squid is susceptible to a Memory Corruption error. This error can lead to a Denial of Service attack.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
None
Integrity
None
Availability
High
Affected products
- squid-cache / squid>= 3.0, <= 3.5.28 – >= 3.0, <= 3.5.28
- squid-cache / squid>= 4.0, <= 4.16 – >= 4.0, <= 4.16
- squid-cache / squid>= 5.0, <= 5.9 – >= 5.0, <= 5.9
- squid-cache / squid>= 6.0, <= 6.9 – >= 6.0, <= 6.9
Updated 21m ago · 8 sources