Resource management error in Squid - CVE-2024-45802
Published: October 28, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to improper management of internal resources within the application when processing ESI response content. A remote attacker can pass specially crafted data to the application and perform a denial of service (DoS) attack.
Successful exploitation of the vulnerability requires that Squid is acting as reverse proxy where ESI feature has been enabled at build time.
Affected software
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
openEuler
Fedora
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libecap
libecap-devel
squid-sysvinit
squid-migration-script
squid
squid (Red Hat package)
squid-debugsource
squid-debuginfo
squid-doc
Session Smart Router
How to mitigate CVE-2024-45802
libecap - update to 1.0.1-2.0.1
libecap-devel - update to 1.0.1-2.0.1
squid-sysvinit - update to 3.5.20-17
squid-migration-script - update to 3.5.20-17
squid - addressed in versions 3.5.20-17, 4.15-13, 6.11-3
squid (Red Hat package) - addressed in versions 3.5.20-17.el7_9.11, 5.2-1.el9_0.7, 5.5-5.el9_2.8, 5.5-13.el9_4.2, 5.5-14.el9_5.3
Session Smart Router - addressed in versions 6.2.10, 6.3.7
squid-debugsource - update to 6.6-4
squid-debuginfo - update to 6.6-4
squid - update to 6.6-4
squid-doc - update to 6.11-3
squid - addressed in versions 6.12-2.fc39, 6.12-2.fc40, 6.12-2.fc41
External References
Related Security Bulletins
- Denial of service in Squid
- openEuler update for squid
- Fedora 40 update for squid
- Fedora 41 update for squid
- Fedora 39 update for squid
- Red Hat Enterprise Linux 8 update for the squid:4 module
- Red Hat Enterprise Linux 9 update for squid
- Red Hat Enterprise Linux 8 update for the squid:4 module
- Red Hat Enterprise Linux 9 update for squid
- Red Hat Enterprise Linux 9 update for squid
- Red Hat Enterprise Linux 9 update for squid
- Red Hat Enterprise Linux 7 Extended Lifecycle Support update for squid
- Red Hat Enterprise Linux 8 update for the squid:4 module
- Red Hat Enterprise Linux 8 update for the squid:4 module
- Red Hat Enterprise Linux 8 update for the squid:4 module
- Anolis OS update for squid:4 module
- Anolis OS update for squid
- Anolis OS update for squid
- Anolis OS update for squid
- Juniper Session Smart Router update for third-party components