PT-2018-9215 · Squid+5 · Squid Http Caching Proxy+6
Louis Dion-Marcil
·
Published
2018-01-29
·
Updated
2024-06-15
·
CVE-2018-1000024
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions:
Squid HTTP Caching Proxy versions 3.0 through 3.5.27
Squid HTTP Caching Proxy versions 4.0 through 4.0.22
Description:
The issue is related to Incorrect Pointer Handling in ESI Response Processing, which can cause Denial of Service for all clients using the proxy. This can be exploited when a remote server delivers an HTTP response payload containing valid but unusual ESI syntax.
Recommendations:
For Squid HTTP Caching Proxy versions 3.0 through 3.5.27, update to version 4.0.23 or later.
For Squid HTTP Caching Proxy versions 4.0 through 4.0.22, update to version 4.0.23 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Centos
Red Hat
Squid Cache
Squid Http Caching Proxy
Suse
Ubuntu