Squid Security Update Advisory (CVE-2024-45802)

Overview

 

An update has been released to address vulnerabilities in Squid. Users of the affected versions are advised to update to the latest version.

 

Affected Products

 

CVE-2024-45802

  • Squid versions: 3.0 (inclusive) ~ 6.9 (inclusive)

 

 

Resolved Vulnerabilities

 

DoS vulnerability due to input validation, resource premature release, and resource leak issues (CVE-2024-45802)

 

Vulnerability Patches

 

Vulnerability Patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

 

CVE-2024-45802

  • Squid version: 6.10

 

 

Referenced Sites

 

[1] CVE-2024-45802 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-45802

[2] Squid-2024:4 Multiple issues in ESI

https://github.com/squid-cache/squid/security/advisories/GHSA-f975-v7qw-q7hj