PT-2025-31674 · Squid +1 · Squid +1

Starrynight

·

Published

2025-08-01

·

Updated

2025-08-04

·

CVE-2025-54574

CVSS v3.1
9.3
VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:H

Name of the Vulnerable Software and Affected Versions:

Squid versions 6.3 and below

Description:

Squid is vulnerable to a heap buffer overflow and possible remote code execution when processing URN due to incorrect buffer management. This issue allows a remote server to perform a buffer overflow attack when delivering URN Trivial-HTTP responses.

Recommendations:

Upgrade to version 6.4.

Disable URN access permissions.

Fix

RCE

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2025-54574
GHSA-W4GV-VW3F-29G3

Affected Products

Debian
Squid