QID 379320
Date Published: 2024-02-28
QID 379320: Squid Proxy Denial of Service (DoS) Vulnerability (SQUID-2023:11)
Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. It reduces bandwidth and improves response times by caching and reusing frequently-requested web pages.
CVE-2024-23638 - Due to an expired pointer reference bug Squid is vulnerable to a Denial of Service attack against Cache Manager error responses.
Affected Versions:
Squid from 0.x to v5.9
Squid from 6.x to 6.5
QID Detection Logic:(Authenticated)
Linux - This QID checks for vulnerable version of Squid by utilizing the command: /usr/sbin/squid -v and /usr/local/squid/sbin/squid -v.
Successful exploitation of this vulnerability can result in Denial of Service
Solution
Customers are advised to upgrade to a fixed version of
later version of Squid to remediate this vulnerability.
Refer, Advisory.
Refer, Advisory.
Vendor References
CVEs related to QID 379320
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SQUID-2023:11 |
|