Back

HIGH

SQUID-2021:8 Denial of Service in Gopher gateway

Published Nov 6, 2023

Description

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a NULL pointer dereference bug Squid is vulnerable to a Denial of Service attack against Squid's Gopher gateway. The gopher protocol is always available and enabled in Squid prior to Squid 6.0.1. Responses triggering this bug are possible to be received from any gopher server, even those without malicious intent. Gopher support has been removed in Squid version 6.0.1. Users are advised to upgrade. Users unable to upgrade should reject all gopher URL requests.

Affected products

Remediation

Red Hat mitigation

To mitigate this issue, create an access list configuration to reject all gopher URL requests: Set ACL directives in your squid.conf file (or equivalent) as follows: acl gopher proto gopher http_access deny gopher Important: This sequence must be placed above any lines starting with "http_access allow" in your configuration. Observation: Some loss of performance may occur with this configuration.

Metrics

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Nov 6, 2023
Updated Nov 3, 2025
Reserved Oct 25, 2023
CISA Vulnrichment
Updated Nov 27, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Sep 26, 2023