CVE-2024-25111
Last modified
CVE-2024-25111 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Squid is a web proxy cache. Starting in version 3.5.27 and prior to version 6.8, Squid may be vulnerable to a Denial of Service attack against HTTP Chunked decoder due to an uncontrolled recursion bug. EPSS estimates a 65.25% chance of exploitation in the next 30 days.
Description
Squid is a web proxy cache. Starting in version 3.5.27 and prior to version 6.8, Squid may be vulnerable to a Denial of Service attack against HTTP Chunked decoder due to an uncontrolled recursion bug. This problem allows a remote attacker to cause Denial of Service when sending a crafted, chunked, encoded HTTP Message. This bug is fixed in Squid version 6.8. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. There is no workaround for this issue.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Squid-Cache | Squid | >= 3.5.27, < 6.8 |
| Fedoraproject | Fedora | 38 |
| Fedoraproject | Fedora | 39 |
| Netapp | Bluexp | All versions |
References
- http://www.squid-cache.org/Versions/v6/SQUID-2024_1.patchMailing List, Patch
- https://security.netapp.com/advisory/ntap-20240605-0001/Third Party Advisory
- http://www.squid-cache.org/Versions/v6/SQUID-2024_1.patchMailing List, Patch
- https://security.netapp.com/advisory/ntap-20240605-0001/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-25111?
How severe is CVE-2024-25111?
How do I fix CVE-2024-25111?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-25106OpenObserve is a observability platform built specifically f…6.5
- CVE-2024-25107WikiDiscover is an extension designed for use with a CreateW…6.1
- CVE-2024-25108Pixelfed is an open source photo sharing platform. When proc…8.8
- CVE-2024-25109ManageWiki is a MediaWiki extension allowing users to manage…5.4
- CVE-2024-2511Issue summary: Some non-default TLS server configurations ca…5.9
- CVE-2024-25110The UAMQP is a general purpose C library for AMQP 1.0. Durin…8.1
- CVE-2024-25112Exiv2 is a command-line utility and C++ library for reading,…5
- CVE-2024-25113Rejected reason: This CVE was misassigned. See CVE-2023-4762…
- CVE-2024-25114Collabora Online is a collaborative online office suite base…5.3
- CVE-2024-25115RedisBloom adds a set of probabilistic data structures to Re…7
- CVE-2024-25116RedisBloom adds a set of probabilistic data structures to Re…5.5
- CVE-2024-25117php-svg-lib is a scalable vector graphics (SVG) file parsing…9.8
Are you affected by CVE-2024-25111?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
