cbcvebase.

Debian Squid vulnerabilities

120 known vulnerabilities affecting debian/squid.

Total CVEs
120
CISA KEV
0
Public exploits
9
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH39MEDIUM50LOW17

Vulnerabilities

Page 5 of 6
CVE-2023-46846P3CRITICALCVSS 9.3fixed in squid 5.7-2+deb12u1 (bookworm)2023
CVE-2023-46846 [CRITICAL] CVE-2023-46846: squid - SQUID is vulnerable to HTTP request smuggling, caused by chunked decoder lenienc... SQUID is vulnerable to HTTP request smuggling, caused by chunked decoder lenience, allows a remote attacker to perform Request/Response smuggling past firewall and frontend security systems. Scope: local bookworm: resolved (fixed in 5.7-2+deb12u1) bullseye: resolved (fixed in 4.13-10+deb11u3) forky: resolved (fixed in 6.5-1) sid: resolved (fixed in 6.5-1) trixie:
debian
CVE-2016-2390P4LOWCVSS 5.9fixed in squid 4.1-1 (bookworm)2016
CVE-2016-2390 [MEDIUM] CVE-2016-2390: squid - The FwdState::connectedToPeer method in FwdState.cc in Squid before 3.5.14 and 4... The FwdState::connectedToPeer method in FwdState.cc in Squid before 3.5.14 and 4.0.x before 4.0.6 does not properly handle SSL handshake errors when built with the --with-openssl option, which allows remote attackers to cause a denial of service (application crash) via a plaintext HTTP message. Scope: local bookworm: resolved (fixed in 4.1-1) bullseye: resolved (fixed
debian
CVE-2009-2855P4LOWCVSS 5.0fixed in squid 2.7.STABLE7-1 (bookworm)2009
CVE-2009-2855 [MEDIUM] CVE-2009-2855: squid - The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allows remote ... The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allows remote attackers to cause a denial of service via a crafted auth header with certain comma delimiters that trigger an infinite loop of calls to the strcspn function. Scope: local bookworm: resolved (fixed in 2.7.STABLE7-1) bullseye: resolved (fixed in 2.7.STABLE7-1) forky: resolved (fixed in 2.7.
debian
CVE-2012-5643P4MEDIUMCVSS 5.0fixed in squid 2.7.STABLE9-2 (bookworm)2012
CVE-2012-5643 [MEDIUM] CVE-2012-5643: squid - Multiple memory leaks in tools/cachemgr.cc in cachemgr.cgi in Squid 2.x and 3.x ... Multiple memory leaks in tools/cachemgr.cc in cachemgr.cgi in Squid 2.x and 3.x before 3.1.22, 3.2.x before 3.2.4, and 3.3.x before 3.3.0.2 allow remote attackers to cause a denial of service (memory consumption) via (1) invalid Content-Length headers, (2) long POST requests, or (3) crafted authentication credentials. Scope: local bookworm: resolved (fixed in 2.7.STAB
debian
CVE-2002-0916P3HIGHCVSS 7.5fixed in squid 2.4.7 (bookworm)2002
CVE-2002-0916 [HIGH] CVE-2002-0916: squid - Format string vulnerability in the allowuser code for the Stellar-X msntauth aut... Format string vulnerability in the allowuser code for the Stellar-X msntauth authentication module, as distributed in Squid 2.4.STABLE6 and earlier, allows remote attackers to execute arbitrary code via format strings in the user name, which are not properly handled in a syslog call. Scope: local bookworm: resolved (fixed in 2.4.7) bullseye: resolved (fixed in 2.4.7) fo
debian
CVE-2021-46784P3MEDIUMCVSS 6.5fixed in squid 5.6-1 (bookworm)2021
CVE-2021-46784 [MEDIUM] CVE-2021-46784: squid - In Squid 3.x through 3.5.28, 4.x through 4.17, and 5.x before 5.6, due to improp... In Squid 3.x through 3.5.28, 4.x through 4.17, and 5.x before 5.6, due to improper buffer management, a Denial of Service can occur when processing long Gopher server responses. Scope: local bookworm: resolved (fixed in 5.6-1) bullseye: resolved (fixed in 4.13-10+deb11u1) forky: resolved (fixed in 5.6-1) sid: resolved (fixed in 5.6-1) trixie: resolved (fixed in 5.6-
debian
CVE-2022-41317P3MEDIUMCVSS 6.5fixed in squid 5.7-1 (bookworm)2022
CVE-2022-41317 [MEDIUM] CVE-2022-41317: squid - An issue was discovered in Squid 4.9 through 4.17 and 5.0.6 through 5.6. Due to ... An issue was discovered in Squid 4.9 through 4.17 and 5.0.6 through 5.6. Due to inconsistent handling of internal URIs, there can be Exposure of Sensitive Information about clients using the proxy via an HTTPS request to an internal cache manager URL. This is fixed in 5.7. Scope: local bookworm: resolved (fixed in 5.7-1) bullseye: resolved (fixed in 4.13-10+deb11u2)
debian
CVE-2005-0446P4MEDIUMCVSS 5.0fixed in squid 2.5.8-3 (bookworm)2005
CVE-2005-0446 [MEDIUM] CVE-2005-0446: squid - Squid 2.5.STABLE8 and earlier allows remote attackers to cause a denial of servi... Squid 2.5.STABLE8 and earlier allows remote attackers to cause a denial of service (crash) via certain DNS responses regarding (1) Fully Qualified Domain Names (FQDN) in fqdncache.c or (2) IP addresses in ipcache.c, which trigger an assertion failure. Scope: local bookworm: resolved (fixed in 2.5.8-3) bullseye: resolved (fixed in 2.5.8-3) forky: resolved (fixed in 2.5
debian
CVE-2019-18677P4MEDIUMCVSS 6.1fixed in squid 4.9-1 (bookworm)2019
CVE-2019-18677 [MEDIUM] CVE-2019-18677: squid - An issue was discovered in Squid 3.x and 4.x through 4.8 when the append_domain ... An issue was discovered in Squid 3.x and 4.x through 4.8 when the append_domain setting is used (because the appended characters do not properly interact with hostname length restrictions). Due to incorrect message processing, it can inappropriately redirect traffic to origins it should not be delivered to. Scope: local bookworm: resolved (fixed in 4.9-1) bullseye:
debian
CVE-2019-12521P4MEDIUMCVSS 5.9fixed in squid 4.11-1 (bookworm)2019
CVE-2019-12521 [MEDIUM] CVE-2019-12521: squid - An issue was discovered in Squid through 4.7. When Squid is parsing ESI, it keep... An issue was discovered in Squid through 4.7. When Squid is parsing ESI, it keeps the ESI elements in ESIContext. ESIContext contains a buffer for holding a stack of ESIElements. When a new ESIElement is parsed, it is added via addStackElement. addStackElement has a check for the number of elements in this buffer, but it's off by 1, leading to a Heap Overflow of 1 e
debian
CVE-2007-1560P4LOWCVSS 5.0fixed in squid 2.6.5-6 (bookworm)2007
CVE-2007-1560 [MEDIUM] CVE-2007-1560: squid - The clientProcessRequest() function in src/client_side.c in Squid 2.6 before 2.6... The clientProcessRequest() function in src/client_side.c in Squid 2.6 before 2.6.STABLE12 allows remote attackers to cause a denial of service (daemon crash) via crafted TRACE requests that trigger an assertion error. Scope: local bookworm: resolved (fixed in 2.6.5-6) bullseye: resolved (fixed in 2.6.5-6) forky: resolved (fixed in 2.6.5-6) sid: resolved (fixed in 2.6.
debian
CVE-2002-0714P4HIGHCVSS 7.5fixed in squid 2.4.6 (bookworm)2002
CVE-2002-0714 [HIGH] CVE-2002-0714: squid - FTP proxy in Squid before 2.4.STABLE6 does not compare the IP addresses of contr... FTP proxy in Squid before 2.4.STABLE6 does not compare the IP addresses of control and data connections with the FTP server, which allows remote attackers to bypass firewall rules or spoof FTP server responses. Scope: local bookworm: resolved (fixed in 2.4.6) bullseye: resolved (fixed in 2.4.6) forky: resolved (fixed in 2.4.6) sid: resolved (fixed in 2.4.6) trixie: reso
debian
CVE-2007-6239P4MEDIUMCVSS 5.0fixed in squid 2.6.17-1 (bookworm)2007
CVE-2007-6239 [MEDIUM] CVE-2007-6239: squid - The "cache update reply processing" functionality in Squid 2.x before 2.6.STABLE... The "cache update reply processing" functionality in Squid 2.x before 2.6.STABLE17 and Squid 3.0 allows remote attackers to cause a denial of service (crash) via unknown vectors related to HTTP headers and an Array memory leak during requests for cached objects. Scope: local bookworm: resolved (fixed in 2.6.17-1) bullseye: resolved (fixed in 2.6.17-1) forky: resolved
debian
CVE-2019-18860P4LOWCVSS 6.1fixed in squid 4.9-1 (bookworm)2019
CVE-2019-18860 [MEDIUM] CVE-2019-18860: squid - Squid before 4.9, when certain web browsers are used, mishandles HTML in the hos... Squid before 4.9, when certain web browsers are used, mishandles HTML in the host (aka hostname) parameter to cachemgr.cgi. Scope: local bookworm: resolved (fixed in 4.9-1) bullseye: resolved (fixed in 4.9-1) forky: resolved (fixed in 4.9-1) sid: resolved (fixed in 4.9-1) trixie: resolved (fixed in 4.9-1)
debian
CVE-2018-19132P4LOWCVSS 5.9fixed in squid 4.4-1 (bookworm)2018
CVE-2018-19132 [MEDIUM] CVE-2018-19132: squid - Squid before 4.4, when SNMP is enabled, allows a denial of service (Memory Leak)... Squid before 4.4, when SNMP is enabled, allows a denial of service (Memory Leak) via an SNMP packet. Scope: local bookworm: resolved (fixed in 4.4-1) bullseye: resolved (fixed in 4.4-1) forky: resolved (fixed in 4.4-1) sid: resolved (fixed in 4.4-1) trixie: resolved (fixed in 4.4-1)
debian
CVE-2002-0713P4HIGHCVSS 7.5fixed in squid 2.4.6-2 (bookworm)2002
CVE-2002-0713 [HIGH] CVE-2002-0713: squid - Buffer overflows in Squid before 2.4.STABLE6 allow remote attackers to cause a d... Buffer overflows in Squid before 2.4.STABLE6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code (1) via the MSNT auth helper (msnt_auth) when using denyusers or allowusers files, (2) via the gopher client, or (3) via the FTP server directory listing parser when HTML output is generated. Scope: local bookworm: resolved (fixed
debian
CVE-2010-0308P4MEDIUMCVSS 4.0fixed in squid 2.7.STABLE8-1 (bookworm)2010
CVE-2010-0308 [MEDIUM] CVE-2010-0308: squid - lib/rfc1035.c in Squid 2.x, 3.0 through 3.0.STABLE22, and 3.1 through 3.1.0.15 a... lib/rfc1035.c in Squid 2.x, 3.0 through 3.0.STABLE22, and 3.1 through 3.1.0.15 allows remote attackers to cause a denial of service (assertion failure) via a crafted DNS packet that only contains a header. Scope: local bookworm: resolved (fixed in 2.7.STABLE8-1) bullseye: resolved (fixed in 2.7.STABLE8-1) forky: resolved (fixed in 2.7.STABLE8-1) sid: resolved (fixed i
debian
CVE-2005-1345P4HIGHCVSS 7.5fixed in squid 2.5.9-7 (bookworm)2005
CVE-2005-1345 [HIGH] CVE-2005-1345: squid - Squid 2.5.STABLE9 and earlier does not trigger a fatal error when it identifies ... Squid 2.5.STABLE9 and earlier does not trigger a fatal error when it identifies missing or invalid ACLs in the http_access configuration, which could lead to less restrictive ACLs than intended by the administrator. Scope: local bookworm: resolved (fixed in 2.5.9-7) bullseye: resolved (fixed in 2.5.9-7) forky: resolved (fixed in 2.5.9-7) sid: resolved (fixed in 2.5.9-7)
debian
CVE-2009-0801P4LOWCVSS 5.4fixed in squid 4.1-1 (bookworm)2009
CVE-2009-0801 [MEDIUM] CVE-2009-0801: squid - Squid, when transparent interception mode is enabled, uses the HTTP Host header ... Squid, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web page that causes a client to send HTTP requests with a modifie
debian
CVE-2021-28652P4MEDIUMCVSS 4.9fixed in squid 4.13-10 (bookworm)2021
CVE-2021-28652 [MEDIUM] CVE-2021-28652: squid - An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to incorr... An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to incorrect parser validation, it allows a Denial of Service attack against the Cache Manager API. This allows a trusted client to trigger memory leaks that. over time, lead to a Denial of Service via an unspecified short query string. This attack is limited to clients with Cache Manager API acc
debian
Debian Squid vulnerabilities | cvebase