Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Debian: DSA-5751-1 Critical: Squid Memory Corruption Threat

debian
Calendar Grey August 19, 2024
Debian Logo
Enhance squid software versions to address severe memory vulnerabilities in Debian's stable releases stemming from ESI decoding concerns.
Joshua Rogers that incorrect parsing of ESI variables in the Squid proxy caching server could result in memory corruption

Summary

Joshua Rogers that incorrect parsing of ESI variables in the Squid proxy
caching server could result in memory corruption.

For the stable distribution (bookworm), this problem has been fixed in
version 5.7-2+deb12u2.

We recommend that you upgrade your squid packages.

For the detailed security status of squid please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/squid

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: squid
CVE ID: CVE-2024-37894

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here