QID 375570

Date Published: 2021-05-18

QID 375570: Squid Multiple Denial Of Service Vulnerability (SQUID-2021:1,SQUID-2021:2,SQUID-2021:3,SQUID-2021:4,SQUID-2021:5)

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. It reduces bandwidth and improves response times by caching and reusing frequently-requested web pages.

Affected Versions:
SQUID-2021:1 : Squid from 2.0 to 4.14 and from 5.0.1 to 5.0.5
SQUID-2021:2 : Squid from 4.0.1 to 4.14 and from 5.0.1 to 5.0.5
SQUID-2021:3 : Squid from 1.0 to 4.14 and from 5.0 to 5.0.5
SQUID-2021:4 : Squid from 2.5.STABLE2 to 2.7.STABLE9 and from 3.0 to 4.1.4 and from 5.0.1 to 5.0.5
SQUID-2021:5 : Squid less than 4.15 and from 5.0 to 5.0.5

QID Detection Logic:
This QID checks for vulnerable version of Squid.

Successful exploitation of these vulnerabilities may allow an attacker to crash squid against all clients using the proxy.

  • CVSS V3 rated as Critical - 8.6 severity.
  • CVSS V2 rated as Critical - 8.3 severity.
  • Solution
    Customers are advised to upgrade to a fixed version of later version of Squid to remediate this vulnerability.
    Software Advisories
    Advisory ID Software Component Link
    Squid URL Logo squid-cache.org/Download/