PT-2018-9215 · Squid+5 · Squid Http Caching Proxy+6

Louis Dion-Marcil

·

Published

2018-01-29

·

Updated

2024-06-15

·

CVE-2018-1000024

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Squid HTTP Caching Proxy versions 3.0 through 3.5.27 Squid HTTP Caching Proxy versions 4.0 through 4.0.22
Description: The issue is related to Incorrect Pointer Handling in ESI Response Processing, which can cause Denial of Service for all clients using the proxy. This can be exploited when a remote server delivers an HTTP response payload containing valid but unusual ESI syntax.
Recommendations: For Squid HTTP Caching Proxy versions 3.0 through 3.5.27, update to version 4.0.23 or later. For Squid HTTP Caching Proxy versions 4.0 through 4.0.22, update to version 4.0.23 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALT-PU-2018-2314
CESA-2020_1068
CVE-2018-1000024
DLA-1266-1
DSA-4122-1
OPENSUSE-SU-2024:11403-1
RHSA-2020:1068
RHSA-2020_1068
SUSE-SU-2018:0636-1
SUSE-SU-2018:0752-1
SUSE-SU-2018_0636-1
SUSE-SU-2018_0752-1
USN-3557-1
USN-4059-2

Affected Products

Alt Linux
Centos
Red Hat
Squid Cache
Squid Http Caching Proxy
Suse
Ubuntu