Expired Pointer Dereference Affecting squid package, versions [,6.6)


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
1.1% (85th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-SQUID-6186449
  • published25 Jan 2024
  • disclosed24 Jan 2024
  • creditJoshua Rogers

Introduced: 24 Jan 2024

CVE-2024-23638  (opens in a new tab)
CWE-825  (opens in a new tab)

How to fix?

Upgrade squid to version 6.6 or higher.

Overview

Affected versions of this package are vulnerable to Expired Pointer Dereference due to an expired pointer reference bug. An attacker can exploit the expired pointer reference when generating error pages for Client Manager reports.

Notes:

  1. This is only exploitable if the attacker is a trusted client.

  2. If you are using a prepackaged version of Squid then please refer to the package vendor for availability information on updated packages.

Workaround

This vulnerability can be mitigated by preventing access to Cache Manager using Squid's main access control: http_access deny manager.

CVSS Scores

version 3.1