Free and open-source vulnerability scanner

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

Squid Proxy Cache Security Update Advisory SQUID-2018:2 (Linux)

Information

Severity

Severity

Medium

Family

Family

Web application abuses

CVSSv2 Base

CVSSv2 Base

5.0

CVSSv2 Vector

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:P

Solution Type

Solution Type

Vendor Patch

Created

Created

6 years ago

Modified

Modified

4 years ago

Summary

Squid is vulnerable to denial of service attack when processing ESI responses. This NVT has been deprecated and merged into 'Squid Proxy Cache Security Update Advisory SQUID-2018:2' (OID:1.3.6.1.4.1.25623.1.0.107297)

Insight

Insight

Due to incorrect pointer handling Squid is vulnerable to denial of service attack when processing ESI responses or downloading intermediate CA certificates.

Affected Software

Affected Software

Squid 3.x -> 3.5.27, Squid 4.x -> 4.0.22.

Detection Method

Detection Method

Checks if a vulnerable version is present on the target host.

Solution

Solution

Updated Packages: This bug is fixed by Squid version 4.0.23. In addition, patches addressing this problem for the stable releases can be found in our patch archives for Squid 3.5 and Squid 4. If you are using a prepackaged version of Squid then please refer to the package vendor for availability information on updated packages.

Common Vulnerabilities and Exposures (CVE)