QID 62084

Date Published: 2024-03-19

QID 62084: Squid Proxy Denial of Service (DoS) Vulnerability (SQUID-2024:1)

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. It reduces bandwidth and improves response times by caching and reusing frequently-requested web pages.
CVE-2024-25111 - Due to an Uncontrolled Recursion bug, Squid may be vulnerable to a Denial of Service attack against HTTP Chunked decoder.

Affected Versions:
Squid from version 3.5.27 to 5.9
Squid from 6.x to 6.7

QID Detection Logic:
This QID finds the SQUID proxy version using banners.

Successful exploitation of this vulnerability allows a remote attacker to perform Denial of Service when sending a crafted chunked encoded HTTP Message.

  • CVSS V3 rated as Critical - 8.6 severity.
  • CVSS V2 rated as High - 6.6 severity.
  • Solution
    Customers are advised to upgrade to a fixed version of Squid to remediate this vulnerability.
    Refer, Advisory.

    CVEs related to QID 62084

    Software Advisories
    Advisory ID Software Component Link
    SQUID-2024:1 URL Logo www.squid-cache.org/Versions/v6/