VDB
WID-SEC-W-2025-2334
WID-SEC-W-2025-2334
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Squid ist ein Open-Source Web Proxy Cache für Unix und Windows Plattformen. Die Software unterstützt Proxying und Caching von HTTP, FTP und anderen Protokollen, sowie SSL und Access Control Lists.
Risk Scores
CVSS 4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Open Source Squid 7.2 | ||
| Securepoint UTM 14.0.9.1 | ||
| Debian Linux | ||
| Oracle Linux | ||
| Securepoint UTM <14.0.9.1 | ||
| Ubuntu Linux | ||
| Amazon Linux 2 | ||
| Red Hat Enterprise Linux | ||
| Open Source Squid <7.2 |
Exploit Intelligence
- Proof-of-Concept (PoC) for CVE-2025-62168 👾 (github-poc)
- https://access.redhat.com/errata/RHSA-2025:19114 (circl)
- https://access.redhat.com/errata/RHSA-2025:19167 (circl)
- https://wiki.securepoint.de/UTM/Changelog (circl)
- https://alas.aws.amazon.com/AL2/ALAS2-2025-3045.html (circl)
- https://access.redhat.com/errata/RHSA-2025:19115 (circl)
- http://linux.oracle.com/errata/ELSA-2025-19107.html (circl)
- https://github.com/squid-cache/squid/security/advisories/GHSA-c8cc-phh7-xmxr (circl)
- https://access.redhat.com/errata/RHSA-2025:19118 (circl)
- https://access.redhat.com/errata/RHSA-2025:19107 (circl)
…and 7 more exploits
Timeline
- Oct 16, 2025 CVE Published
- Nov 2, 2025 CVE Updated
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Distribution Patch
References
- https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-2334.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-2334 advisory
- https://github.com/squid-cache/squid/security/advisories/GHSA-c8cc-phh7-xmxr url
- https://wiki.securepoint.de/UTM/Changelog url
- https://alas.aws.amazon.com/AL2/ALAS2-2025-3045.html url
- https://access.redhat.com/errata/RHSA-2025:19115 url
- http://linux.oracle.com/errata/ELSA-2025-19107.html url
- https://access.redhat.com/errata/RHSA-2025:19118 url
- https://access.redhat.com/errata/RHSA-2025:19114 url
- https://access.redhat.com/errata/RHSA-2025:19107 url
- https://access.redhat.com/errata/RHSA-2025:19167 url
- https://ubuntu.com/security/notices/USN-7845-1 url
- https://access.redhat.com/errata/RHSA-2025:19277 url
- https://lists.debian.org/debian-security-announce/2025/msg00212.html url
- https://github.com/shahroodcert/CVE-2025-62168 url