CRITICAL🇵🇱 Wersja polska

CVE-2025-54574

CVSS 9.3v3.1pub. 2025-08-01upd. 2025-11-05

Squid is a caching proxy for the Web. In versions 6.3 and below, Squid is vulnerable to a heap buffer overflow and possible remote code execution attack when processing URN due to incorrect buffer management. This has been fixed in version 6.4. To work around this issue, disable URN access permissions.

🤖 AI Analysis
How it works

The vulnerability results from improper memory management when handling URN (Uniform Resource Name) protocol-based requests. An attacker sends a specially crafted URN request to a vulnerable Squid instance, causing a heap buffer overflow. This results in memory corruption of the process, which can lead to its crash or – under favorable circumstances – to arbitrary code execution (RCE).

Impact

An attacker can cause proxy service unavailability (DoS) or potentially take control of the system through remote code execution (RCE) without requiring any privileges.

Mitigation & patch

Update Squid to version 6.4, where the issue has been fixed. If an immediate update is not possible, as a workaround, disable URN access permissions in the Squid configuration.

Who is affected

Squid in versions 6.3 and below (Squid-Cache/Squid).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:H
  • Squid Cache Squid

    APP
    Squid-Cache
    < 6.4
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEMemory
CWE
References

Related vulnerabilities

CVE-2026-33526CRITICAL9.2PL ✓same product

Squid: Use-After-Free w obsłudze ruchu ICP umożliwia atak DoS

CVE-2025-62168CRITICAL10.0PL ✓same product

Squid: ujawnienie danych uwierzytelniających HTTP przez błędy obsługi

CVE-2023-46846CRITICAL9.3PL ✓same product

Squid: HTTP request smuggling przez zbyt liberalny dekoder chunked

CVE-2020-15049CRITICAL9.9PL ✓same product

Request Smuggling i cache poisoning w Squid przez nieprawidłowy Content-Length

CVE-2020-11945CRITICAL9.8PL ✓same product

Squid: przepełnienie licznika nonce w Digest Authentication umożliwia RCE