CVE-2024-25617

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Feb 14, 2024
Updated: Mar 22, 2024
CWE ID 182
CWE ID 400

Summary

CVE-2024-25617 is a Denial of Service vulnerability affecting Squid, an open-source web caching proxy. The issue, known as a Collapse of Data into Unsafe Value bug, can be exploited by remote clients or servers sending oversized headers in HTTP messages. In earlier versions of Squid, this vulnerability can lead to a Denial of Service attack due to insufficient size limits for request and reply headers. While Squid version 6.5 and later have safer defaults, the software does not prevent users from setting these parameters to unsafe values, leading to a critical warning in the cache.log file. No known workarounds exist, and users are advised to upgrade to the latest version to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share