Back

HIGH

Squid Denial of Service

Published Oct 28, 2024

Description

Squid is an open source caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to Input Validation, Premature Release of Resource During Expected Lifetime, and Missing Release of Resource after Effective Lifetime bugs, Squid is vulnerable to Denial of Service attacks by a trusted server against all clients using the proxy. This bug is fixed in the default build configuration of Squid version 6.10.

Affected products

Remediation

Red Hat statement

All builds of Squid shipped in supported versions of Red Hat Enterprise Linux are built with the vulnerable (ESI) feature enabled.

Red Hat mitigation

This bug was mitigated by the default upstream build configuration of Squid since version 6.10.

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Oct 28, 2024
Updated Nov 3, 2025
Reserved Sep 9, 2024
CISA Vulnrichment
Updated Oct 28, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Oct 28, 2024