Debian Squid vulnerabilities
120 known vulnerabilities affecting debian/squid.
Total CVEs
120
CISA KEV
0
Public exploits
9
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH39MEDIUM50LOW17
Vulnerabilities
Page 1 of 6
CVE-2025-62168P2CRITICALCVSS 10.0PoCfixed in squid 5.7-2+deb12u4 (bookworm)2025
CVE-2025-62168 [CRITICAL] CVE-2025-62168: squid - Squid is a caching proxy for the Web. In Squid versions prior to 7.2, a failure ...
Squid is a caching proxy for the Web. In Squid versions prior to 7.2, a failure to redact HTTP authentication credentials in error handling allows information disclosure. The vulnerability allows a script to bypass browser security protections and learn the credentials a trusted client uses to authenticate. This potentially allows a remote client to identify secur
debian
CVE-2021-31806P2MEDIUMCVSS 6.5PoCfixed in squid 4.13-10 (bookworm)2021
CVE-2021-31806 [MEDIUM] CVE-2021-31806: squid - An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a memo...
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a memory-management bug, it is vulnerable to a Denial of Service attack (against all clients using the proxy) via HTTP Range request processing.
Scope: local
bookworm: resolved (fixed in 4.13-10)
bullseye: resolved (fixed in 4.13-10)
forky: resolved (fixed in 4.13-10)
sid: resolved (fixed in 4
debian
CVE-2004-0541P2CRITICALCVSS 10.0PoCfixed in squid 2.5.5-5 (bookworm)2004
CVE-2004-0541 [CRITICAL] CVE-2004-0541: squid - Buffer overflow in the ntlm_check_auth (NTLM authentication) function for Squid ...
Buffer overflow in the ntlm_check_auth (NTLM authentication) function for Squid Web Proxy Cache 2.5.x and 3.x, when compiled with NTLM handlers enabled, allows remote attackers to execute arbitrary code via a long password ("pass" variable).
Scope: local
bookworm: resolved (fixed in 2.5.5-5)
bullseye: resolved (fixed in 2.5.5-5)
forky: resolved (fixed in 2.5.5-5)
si
debian
CVE-2020-11945P2CRITICALCVSS 9.8fixed in squid 4.11-1 (bookworm)2020
CVE-2020-11945 [CRITICAL] CVE-2020-11945: squid - An issue was discovered in Squid before 5.0.2. A remote attacker can replay a sn...
An issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resources that are otherwise forbidden. This occurs because the attacker can overflow the nonce reference counter (a short integer). Remote code execution may occur if the pooled token credentials are freed (instead of replayed as val
debian
CVE-2025-54574P2CRITICALCVSS 9.3fixed in squid 5.7-2+deb12u3 (bookworm)2025
CVE-2025-54574 [CRITICAL] CVE-2025-54574: squid - Squid is a caching proxy for the Web. In versions 6.3 and below, Squid is vulner...
Squid is a caching proxy for the Web. In versions 6.3 and below, Squid is vulnerable to a heap buffer overflow and possible remote code execution attack when processing URN due to incorrect buffer management. This has been fixed in version 6.4. To work around this issue, disable URN access permissions.
Scope: local
bookworm: resolved (fixed in 5.7-2+deb12u3)
bulls
debian
CVE-2023-46847P2HIGHCVSS 8.6fixed in squid 5.7-2+deb12u1 (bookworm)2023
CVE-2023-46847 [HIGH] CVE-2023-46847: squid - Squid is vulnerable to a Denial of Service, where a remote attacker can perform...
Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is configured to accept HTTP Digest Authentication.
Scope: local
bookworm: resolved (fixed in 5.7-2+deb12u1)
bullseye: resolved (fixed in 4.13-10+deb11u3)
forky: resolved (fixed in 6.5-1)
sid: resolved
debian
CVE-2023-49285P2HIGHCVSS 8.6fixed in squid 5.7-2+deb12u1 (bookworm)2023
CVE-2023-49285 [HIGH] CVE-2023-49285: squid - Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due ...
Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Buffer Overread bug Squid is vulnerable to a Denial of Service attack against Squid HTTP Message processing. This bug is fixed by Squid version 6.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Scope: local
bookworm: resolved (fixed in 5.7-2+deb
debian
CVE-2024-25617P2MEDIUMCVSS 5.3fixed in squid 5.7-2+deb12u1 (bookworm)2024
CVE-2024-25617 [MEDIUM] CVE-2024-25617: squid - Squid is an open source caching proxy for the Web supporting HTTP, HTTPS, FTP, a...
Squid is an open source caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Collapse of Data into Unsafe Value bug ,Squid may be vulnerable to a Denial of Service attack against HTTP header parsing. This problem allows a remote client or a remote server to perform Denial of Service when sending oversized headers in HTTP messages. In versions of
debian
CVE-2020-8450P2HIGHCVSS 7.3fixed in squid 4.10-1 (bookworm)2020
CVE-2020-8450 [HIGH] CVE-2020-8450: squid - An issue was discovered in Squid before 4.10. Due to incorrect buffer management...
An issue was discovered in Squid before 4.10. Due to incorrect buffer management, a remote client can cause a buffer overflow in a Squid instance acting as a reverse proxy.
Scope: local
bookworm: resolved (fixed in 4.10-1)
bullseye: resolved (fixed in 4.10-1)
forky: resolved (fixed in 4.10-1)
sid: resolved (fixed in 4.10-1)
trixie: resolved (fixed in 4.10-1)
debian
CVE-2019-12527P2HIGHCVSS 8.8fixed in squid 4.8-1 (bookworm)2019
CVE-2019-12527 [HIGH] CVE-2019-12527: squid - An issue was discovered in Squid 4.0.23 through 4.7. When checking Basic Authent...
An issue was discovered in Squid 4.0.23 through 4.7. When checking Basic Authentication with HttpHeader::getAuth, Squid uses a global buffer to store the decoded data. Squid does not check that the decoded length isn't greater than the buffer, leading to a heap-based buffer overflow with user controlled data.
Scope: local
bookworm: resolved (fixed in 4.8-1)
bullseye:
debian
CVE-2009-0478P3MEDIUMCVSS 5.0PoCfixed in squid 2.7.STABLE3-4.1 (bookworm)2009
CVE-2009-0478 [MEDIUM] CVE-2009-0478: squid - Squid 2.7 to 2.7.STABLE5, 3.0 to 3.0.STABLE12, and 3.1 to 3.1.0.4 allows remote ...
Squid 2.7 to 2.7.STABLE5, 3.0 to 3.0.STABLE12, and 3.1 to 3.1.0.4 allows remote attackers to cause a denial of service via an HTTP request with an invalid version number, which triggers a reachable assertion in (1) HttpMsg.c and (2) HttpStatusLine.c.
Scope: local
bookworm: resolved (fixed in 2.7.STABLE3-4.1)
bullseye: resolved (fixed in 2.7.STABLE3-4.1)
forky: resolve
debian
CVE-2021-31807P3MEDIUMCVSS 6.5PoCfixed in squid 4.13-10 (bookworm)2021
CVE-2021-31807 [MEDIUM] CVE-2021-31807: squid - An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. An integer ov...
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. An integer overflow problem allows a remote server to achieve Denial of Service when delivering responses to HTTP Range requests. The issue trigger is a header that can be expected to exist in HTTP traffic without any malicious intent.
Scope: local
bookworm: resolved (fixed in 4.13-10)
bullseye: reso
debian
CVE-2019-12525P2CRITICALCVSS 9.8fixed in squid 4.8-1 (bookworm)2019
CVE-2019-12525 [CRITICAL] CVE-2019-12525: squid - An issue was discovered in Squid 3.3.9 through 3.5.28 and 4.x through 4.7. When ...
An issue was discovered in Squid 3.3.9 through 3.5.28 and 4.x through 4.7. When Squid is configured to use Digest authentication, it parses the header Proxy-Authorization. It searches for certain tokens such as domain, uri, and qop. Squid checks if this token's value starts with a quote and ends with one. If so, it performs a memcpy of its length minus 2. Squid ne
debian
CVE-2023-50269P3HIGHCVSS 8.6fixed in squid 5.7-2+deb12u1 (bookworm)2023
CVE-2023-50269 [HIGH] CVE-2023-50269: squid - Squid is a caching proxy for the Web. Due to an Uncontrolled Recursion bug in ve...
Squid is a caching proxy for the Web. Due to an Uncontrolled Recursion bug in versions 2.6 through 2.7.STABLE9, versions 3.1 through 5.9, and versions 6.0.1 through 6.5, Squid may be vulnerable to a Denial of Service attack against HTTP Request parsing. This problem allows a remote client to perform Denial of Service attack by sending a large X-Forwarded-For header wh
debian
CVE-2024-25111P3HIGHCVSS 8.6fixed in squid 5.7-2+deb12u1 (bookworm)2024
CVE-2024-25111 [HIGH] CVE-2024-25111: squid - Squid is a web proxy cache. Starting in version 3.5.27 and prior to version 6.8,...
Squid is a web proxy cache. Starting in version 3.5.27 and prior to version 6.8, Squid may be vulnerable to a Denial of Service attack against HTTP Chunked decoder due to an uncontrolled recursion bug. This problem allows a remote attacker to cause Denial of Service when sending a crafted, chunked, encoded HTTP Message. This bug is fixed in Squid version 6.8. In addit
debian
CVE-2024-45802P3HIGHCVSS 7.5fixed in squid 5.7-2+deb12u5 (bookworm)2024
CVE-2024-45802 [HIGH] CVE-2024-45802: squid - Squid is an open source caching proxy for the Web supporting HTTP, HTTPS, FTP, a...
Squid is an open source caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to Input Validation, Premature Release of Resource During Expected Lifetime, and Missing Release of Resource after Effective Lifetime bugs, Squid is vulnerable to Denial of Service attacks by a trusted server against all clients using the proxy. This bug is fixed in the defaul
debian
CVE-2019-12526P2CRITICALCVSS 9.8fixed in squid 4.9-1 (bookworm)2019
CVE-2019-12526 [CRITICAL] CVE-2019-12526: squid - An issue was discovered in Squid before 4.9. URN response handling in Squid suff...
An issue was discovered in Squid before 4.9. URN response handling in Squid suffers from a heap-based buffer overflow. When receiving data from a remote server in response to an URN request, Squid fails to ensure that the response can fit within the buffer. This leads to attacker controlled data overflowing in the heap.
Scope: local
bookworm: resolved (fixed in 4.
debian
CVE-2016-4554P2HIGHCVSS 8.6fixed in squid 4.1-1 (bookworm)2016
CVE-2016-4554 [HIGH] CVE-2016-4554: squid - mime_header.cc in Squid before 3.5.18 allows remote attackers to bypass intended...
mime_header.cc in Squid before 3.5.18 allows remote attackers to bypass intended same-origin restrictions and possibly conduct cache-poisoning attacks via a crafted HTTP Host header, aka a "header smuggling" issue.
Scope: local
bookworm: resolved (fixed in 4.1-1)
bullseye: resolved (fixed in 4.1-1)
forky: resolved (fixed in 4.1-1)
sid: resolved (fixed in 4.1-1)
trixie:
debian
CVE-2019-18679P3HIGHCVSS 7.5fixed in squid 4.9-1 (bookworm)2019
CVE-2019-18679 [HIGH] CVE-2019-18679: squid - An issue was discovered in Squid 2.x, 3.x, and 4.x through 4.8. Due to incorrect...
An issue was discovered in Squid 2.x, 3.x, and 4.x through 4.8. Due to incorrect data management, it is vulnerable to information disclosure when processing HTTP Digest Authentication. Nonce tokens contain the raw byte value of a pointer that sits within heap memory allocation. This information reduces ASLR protections and may aid attackers isolating memory areas to t
debian
CVE-2021-33620P3MEDIUMCVSS 6.5fixed in squid 4.13-10 (bookworm)2021
CVE-2021-33620 [MEDIUM] CVE-2021-33620: squid - Squid before 4.15 and 5.x before 5.0.6 allows remote servers to cause a denial o...
Squid before 4.15 and 5.x before 5.0.6 allows remote servers to cause a denial of service (affecting availability to all clients) via an HTTP response. The issue trigger is a header that can be expected to exist in HTTP traffic without any malicious intent by the server.
Scope: local
bookworm: resolved (fixed in 4.13-10)
bullseye: resolved (fixed in 4.13-10)
forky:
debian
1 / 6Next →