VDB

CESS-2025-54574

CESS-2025-54574 PUBLISHED CVSS 9.8 CRITICAL

Squid is a caching proxy for the Web. In versions 6.3 and below, Squid is vulnerable to a heap buffer overflow and possible remote code execution attack when processing URN due to incorrect buffer management. This has been fixed in version 6.4. To work around this issue, disable URN access permissions.

Risk Scores

CVSS 3.1
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Timeline

  • Apr 2, 2024 CVE Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›