Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in the FTP gateway (src/clients/FtpGateway.cc), Squid is vulnerable to an out-of-bounds read: when a listing entry date in the TypeA or TypeB directory-listing formats is not followed by a filename, parsing was not restricted to the input buffer, so a trusted client accessing a misbehaving FTP server through Squid's gateway feature could read memory from random unrelated transactions. This issue is fixed in version 7.6.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NSquid Cache Squid
APPSquid-Cache< 7.6
Related vulnerabilities
Squid: Use-After-Free w obsłudze ruchu ICP umożliwia atak DoS
Squid: ujawnienie danych uwierzytelniających HTTP przez błędy obsługi
Heap buffer overflow w Squid podczas przetwarzania URN – możliwy RCE
Squid: HTTP request smuggling przez zbyt liberalny dekoder chunked
Request Smuggling i cache poisoning w Squid przez nieprawidłowy Content-Length