VDB

DEBIAN-CVE-2025-54574

DEBIAN-CVE-2025-54574 PUBLISHED CVSS 9.800000190734863 CRITICAL

Squid is a caching proxy for the Web. In versions 6.3 and below, Squid is vulnerable to a heap buffer overflow and possible remote code execution attack when processing URN due to incorrect buffer management. This has been fixed in version 6.4. To work around this issue, disable URN access permissions.

Risk Scores

CVSS 3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
Debian:11squid0, 4.13-10+deb11u1, 4.13-10+deb11u2
Debian:12squid0, 5.7-2, 5.7-2+deb12u1
Debian:14squid0, 0
Debian:13squid0, 0

Timeline

  • Aug 1, 2025 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›