cbcvebase.

Debian Squid vulnerabilities

120 known vulnerabilities affecting debian/squid.

Total CVEs
120
CISA KEV
0
Public exploits
9
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH39MEDIUM50LOW17

Vulnerabilities

Page 3 of 6
CVE-2016-3948P3HIGHCVSS 7.5fixed in squid 4.1-1 (bookworm)2016
CVE-2016-3948 [HIGH] CVE-2016-3948: squid - Squid 3.x before 3.5.16 and 4.x before 4.0.8 improperly perform bounds checking,... Squid 3.x before 3.5.16 and 4.x before 4.0.8 improperly perform bounds checking, which allows remote attackers to cause a denial of service via a crafted HTTP response, related to Vary headers. Scope: local bookworm: resolved (fixed in 4.1-1) bullseye: resolved (fixed in 4.1-1) forky: resolved (fixed in 4.1-1) sid: resolved (fixed in 4.1-1) trixie: resolved (fixed in 4.
debian
CVE-2016-3947P3HIGHCVSS 8.2fixed in squid 4.1-1 (bookworm)2016
CVE-2016-3947 [HIGH] CVE-2016-3947: squid - Heap-based buffer overflow in the Icmp6::Recv function in icmp/Icmp6.cc in the p... Heap-based buffer overflow in the Icmp6::Recv function in icmp/Icmp6.cc in the pinger utility in Squid before 3.5.16 and 4.x before 4.0.8 allows remote servers to cause a denial of service (performance degradation or transition failures) or write sensitive information to log files via an ICMPv6 packet. Scope: local bookworm: resolved (fixed in 4.1-1) bullseye: resolved
debian
CVE-2014-6270P3LOWCVSS 6.8fixed in squid 4.1-1 (bookworm)2014
CVE-2014-6270 [MEDIUM] CVE-2014-6270: squid - Off-by-one error in the snmpHandleUdp function in snmp_core.cc in Squid 2.x and ... Off-by-one error in the snmpHandleUdp function in snmp_core.cc in Squid 2.x and 3.x, when an SNMP port is configured, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted UDP SNMP request, which triggers a heap-based buffer overflow. Scope: local bookworm: resolved (fixed in 4.1-1) bullseye: resolved (fixed in 4
debian
CVE-2022-41318P3HIGHCVSS 8.6fixed in squid 5.7-1 (bookworm)2022
CVE-2022-41318 [HIGH] CVE-2022-41318: squid - A buffer over-read was discovered in libntlmauth in Squid 2.5 through 5.6. Due t... A buffer over-read was discovered in libntlmauth in Squid 2.5 through 5.6. Due to incorrect integer-overflow protection, the SSPI and SMB authentication helpers are vulnerable to reading unintended memory locations. In some configurations, cleartext credentials from these locations are sent to a client. This is fixed in 5.7. Scope: local bookworm: resolved (fixed in 5
debian
CVE-2019-18676P3HIGHCVSS 7.5fixed in squid 4.9-1 (bookworm)2019
CVE-2019-18676 [HIGH] CVE-2019-18676: squid - An issue was discovered in Squid 3.x and 4.x through 4.8. Due to incorrect input... An issue was discovered in Squid 3.x and 4.x through 4.8. Due to incorrect input validation, there is a heap-based buffer overflow that can result in Denial of Service to all clients using the proxy. Severity is high due to this vulnerability occurring before normal security checks; any remote client that can reach the proxy port can trivially perform the attack via a
debian
CVE-2019-12528P3HIGHCVSS 7.5fixed in squid 4.10-1 (bookworm)2019
CVE-2019-12528 [HIGH] CVE-2019-12528: squid - An issue was discovered in Squid before 4.10. It allows a crafted FTP server to ... An issue was discovered in Squid before 4.10. It allows a crafted FTP server to trigger disclosure of sensitive information from heap memory, such as information associated with other users' sessions or non-Squid processes. Scope: local bookworm: resolved (fixed in 4.10-1) bullseye: resolved (fixed in 4.10-1) forky: resolved (fixed in 4.10-1) sid: resolved (fixed in 4
debian
CVE-2023-49286P3HIGHCVSS 8.6fixed in squid 5.7-2+deb12u1 (bookworm)2023
CVE-2023-49286 [HIGH] CVE-2023-49286: squid - Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due ... Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to an Incorrect Check of Function Return Value bug Squid is vulnerable to a Denial of Service attack against its Helper process management. This bug is fixed by Squid version 6.5. Users are advised to upgrade. There are no known workarounds for this vulnerability. Scope: local bookworm: re
debian
CVE-2023-46848P3HIGHCVSS 8.6fixed in squid 5.7-2+deb12u1 (bookworm)2023
CVE-2023-46848 [HIGH] CVE-2023-46848: squid - Squid is vulnerable to Denial of Service, where a remote attacker can perform D... Squid is vulnerable to Denial of Service, where a remote attacker can perform DoS by sending ftp:// URLs in HTTP Request messages or constructing ftp:// URLs from FTP Native input. Scope: local bookworm: resolved (fixed in 5.7-2+deb12u1) bullseye: resolved forky: resolved (fixed in 6.5-1) sid: resolved (fixed in 6.5-1) trixie: resolved (fixed in 6.5-1)
debian
CVE-2023-49288P3HIGHCVSS 8.6fixed in squid 6.1-1 (forky)2023
CVE-2023-49288 [HIGH] CVE-2023-49288: squid - Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Affe... Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Affected versions of squid are subject to a a Use-After-Free bug which can lead to a Denial of Service attack via collapsed forwarding. All versions of Squid from 3.5 up to and including 5.9 configured with "collapsed_forwarding on" are vulnerable. Configurations with "collapsed_forwarding off
debian
CVE-2019-12854P3HIGHCVSS 7.5fixed in squid 4.8-1 (bookworm)2019
CVE-2019-12854 [HIGH] CVE-2019-12854: squid - Due to incorrect string termination, Squid cachemgr.cgi 4.0 through 4.7 may acce... Due to incorrect string termination, Squid cachemgr.cgi 4.0 through 4.7 may access unallocated memory. On systems with memory access protections, this can cause the CGI process to terminate unexpectedly, resulting in a denial of service for all clients using it. Scope: local bookworm: resolved (fixed in 4.8-1) bullseye: resolved (fixed in 4.8-1) forky: resolved (fixed
debian
CVE-2019-12520P3HIGHCVSS 7.5fixed in squid 4.8-1 (bookworm)2019
CVE-2019-12520 [HIGH] CVE-2019-12520: squid - An issue was discovered in Squid through 4.7 and 5. When receiving a request, Sq... An issue was discovered in Squid through 4.7 and 5. When receiving a request, Squid checks its cache to see if it can serve up a response. It does this by making a MD5 hash of the absolute URL of the request. If found, it servers the request. The absolute URL can include the decoded UserInfo (username and password) for certain protocols. This decoded info is prepended
debian
CVE-2018-1000027P3HIGHCVSS 7.5fixed in squid 4.1-1 (bookworm)2018
CVE-2018-1000027 [HIGH] CVE-2018-1000027: squid - The Squid Software Foundation Squid HTTP Caching Proxy version prior to version ... The Squid Software Foundation Squid HTTP Caching Proxy version prior to version 4.0.23 contains a NULL Pointer Dereference vulnerability in HTTP Response X-Forwarded-For header processing that can result in Denial of Service to all clients of the proxy. This attack appear to be exploitable via Remote HTTP server responding with an X-Forwarded-For header to certain
debian
CVE-2020-8517P3LOWCVSS 7.5fixed in squid 4.10-1 (bookworm)2020
CVE-2020-8517 [HIGH] CVE-2020-8517: squid - An issue was discovered in Squid before 4.10. Due to incorrect input validation,... An issue was discovered in Squid before 4.10. Due to incorrect input validation, the NTLM authentication credentials parser in ext_lm_group_acl may write to memory outside the credentials buffer. On systems with memory access protections, this can result in the helper process being terminated unexpectedly. This leads to the Squid process also terminating and a denial of
debian
CVE-2021-41611P3HIGHCVSS 7.5fixed in squid 5.2-1 (bookworm)2021
CVE-2021-41611 [HIGH] CVE-2021-41611: squid - An issue was discovered in Squid 5.0.6 through 5.1.x before 5.2. When validating... An issue was discovered in Squid 5.0.6 through 5.1.x before 5.2. When validating an origin server or peer certificate, Squid may incorrectly classify certain certificates as trusted. This problem allows a remote server to obtain security trust well improperly. This indication of trust may be passed along to clients, allowing access to unsafe or hijacked services. Scop
debian
CVE-2014-3609P3MEDIUMCVSS 5.0fixed in squid 2.7.STABLE9-5 (bookworm)2014
CVE-2014-3609 [MEDIUM] CVE-2014-3609: squid - HttpHdrRange.cc in Squid 3.x before 3.3.12 and 3.4.x before 3.4.6 allows remote ... HttpHdrRange.cc in Squid 3.x before 3.3.12 and 3.4.x before 3.4.6 allows remote attackers to cause a denial of service (crash) via a request with crafted "Range headers with unidentifiable byte-range values." Scope: local bookworm: resolved (fixed in 2.7.STABLE9-5) bullseye: resolved (fixed in 2.7.STABLE9-5) forky: resolved (fixed in 2.7.STABLE9-5) sid: resolved (fixe
debian
CVE-2018-1000024P3HIGHCVSS 7.5fixed in squid 4.1-1 (bookworm)2018
CVE-2018-1000024 [HIGH] CVE-2018-1000024: squid - The Squid Software Foundation Squid HTTP Caching Proxy version 3.0 to 3.5.27, 4.... The Squid Software Foundation Squid HTTP Caching Proxy version 3.0 to 3.5.27, 4.0 to 4.0.22 contains a Incorrect Pointer Handling vulnerability in ESI Response Processing that can result in Denial of Service for all clients using the proxy.. This attack appear to be exploitable via Remote server delivers an HTTP response payload containing valid but unusual ESI sy
debian
CVE-2023-46728P3HIGHCVSS 7.5fixed in squid 5.7-2+deb12u5 (bookworm)2023
CVE-2023-46728 [HIGH] CVE-2023-46728: squid - Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due ... Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a NULL pointer dereference bug Squid is vulnerable to a Denial of Service attack against Squid's Gopher gateway. The gopher protocol is always available and enabled in Squid prior to Squid 6.0.1. Responses triggering this bug are possible to be received from any gopher server, even thos
debian
CVE-2023-5824P3HIGHCVSS 7.5fixed in squid 5.7-2+deb12u3 (bookworm)2023
CVE-2023-5824 [HIGH] CVE-2023-5824: squid - A flaw was found in Squid. The limits applied for validation of HTTP response he... A flaw was found in Squid. The limits applied for validation of HTTP response headers are applied before caching. However, Squid may grow a cached HTTP response header beyond the configured maximum size, causing a stall or crash of the worker process when a large header is retrieved from the disk cache, resulting in a denial of service. Scope: local bookworm: resolved (
debian
CVE-2005-0211P3HIGHCVSS 7.5fixed in squid 2.5.7-6 (bookworm)2005
CVE-2005-0211 [HIGH] CVE-2005-0211: squid - Buffer overflow in wccp.c in Squid 2.5 before 2.5.STABLE7 allows remote attacker... Buffer overflow in wccp.c in Squid 2.5 before 2.5.STABLE7 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long WCCP packet, which is processed by a recvfrom function call that uses an incorrect length parameter. Scope: local bookworm: resolved (fixed in 2.5.7-6) bullseye: resolved (fixed in 2.5.7-6) forky: resolved (fixed i
debian
CVE-2023-46724P3HIGHCVSS 8.6fixed in squid 5.7-2+deb12u1 (bookworm)2023
CVE-2023-46724 [HIGH] CVE-2023-46724: squid - Squid is a caching proxy for the Web. Due to an Improper Validation of Specified... Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service attack against SSL Certificate validation. This problem allows a remote server to perform Denial of Service against Squid Proxy by initiating a TLS Hand
debian
Debian Squid vulnerabilities | cvebase