PT-2024-4566 · Squid+9 · Squid+10

Joshua Rogers

·

Published

2024-06-25

·

Updated

2026-03-29

·

CVE-2024-37894

CVSS v3.1

6.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Squid (affected versions not specified)
Description: The issue is related to an Out-of-bounds Write error when assigning ESI variables, which can lead to a Memory Corruption error. This error can result in a Denial of Service attack. The vulnerability can be exploited by a remote attacker to cause a service disruption.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2024:4861
AZL-42871
BDU:2024-05070
CVE-2024-37894
DLA-4083-1
DSA-5751-1
GHSA-WGVF-Q977-9XJG
INFSA-2024_4861
MGASA-2024-0265
OESA-2024-1785
OPENSUSE-SU-2024:14080-1
OPENSUSE-SU-2024_2268-1
OPENSUSE-SU-2024_2269-1
RHSA-2024:4861
RHSA-2024:5906
RHSA-2024_4861
RLSA-2024:4861
SUSE-SU-2024:2268-1
SUSE-SU-2024:2269-1
SUSE-SU-2024:2270-1
SUSE-SU-2024_2268-1
SUSE-SU-2024_2269-1
SUSE-SU-2024_2270-1
SUSE-SU-2025:03521-1
USN-6907-1

Affected Products

Almalinux
Astra Linux
Debian
Linuxmint
Red Hat
Red Os
Rocky Linux
Squid
Squid Cache
Suse
Ubuntu