PT-2023-8983 · Squid+9 · Squid+10

Joshua Rogers

·

Published

2023-10-12

·

Updated

2025-10-06

·

CVE-2024-25617

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Squid versions prior to 6.5
Description Squid is an open source caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Collapse of Data into Unsafe Value bug, Squid may be vulnerable to a Denial of Service attack against HTTP header parsing. This problem allows a remote client or a remote server to perform Denial of Service when sending oversized headers in HTTP messages. The request header max size or reply header max size settings are used to control this behavior. If these settings are unchanged from the default in versions prior to 6.5, the issue can be exploited. In Squid version 6.5 and later, the default setting of these parameters is safe.
Recommendations To resolve the issue, upgrade to Squid version 6.5 or later, as the default settings in these versions are safe. For versions prior to 6.5, consider changing the request header max size and reply header max size settings to safe values to prevent exploitation. As a temporary workaround, consider monitoring the cache.log for critical warnings related to these settings.

Exploit

Fix

RCE

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

ALSA-2024:1375
ALSA-2024:1376
ALSA-2024_1375
ALSA-2024_1376
AZL-42503
BDU:2024-02844
CESA-2024_1375
CVE-2024-25617
DSA-5637-1
GHSA-H5X6-W8MV-XFPR
MGASA-2024-0102
OESA-2024-1162
OPENSUSE-SU-2024:13757-1
OPENSUSE-SU-2024_1113-1
RHSA-2024:1062
RHSA-2024:1066
RHSA-2024:1184
RHSA-2024:1375
RHSA-2024:1376
RHSA-2024:1787
RHSA-2024:1832
RHSA-2024:1833
RHSA-2024:2777
RHSA-2024_1375
RHSA-2024_1376
RHSA-2024_1787
ROSA-SA-2024-2479
SUSE-SU-2024:1113-1
SUSE-SU-2024:1114-1
SUSE-SU-2024:1115-1
USN-6728-1
USN-6728-2
USN-6857-1

Affected Products

Almalinux
Astra Linux
Centos
Linuxmint
Red Hat
Red Os
Rocky Linux
Squid
Squid Cache
Suse
Ubuntu