Squid.Proxy.ESI.Response.Processing.DoS

description-logoDescription

This indicates an attempt to exploit a Denial of Service vulnerability in Squid proxy.
The vulnerability is due to Edge Slides Includes (ESI) handling ESI response packets improperly. A remote attacker may be able to exploit this to cause a denial of service condition on the target via a crafted packet.

affected-products-logoAffected Products

Squid Project Squid 3.x prior to 3.5.18
Squid Project Squid 4.x prior to 4.0.10

Impact logoImpact

Denial of Service: Remote attackers can crash vulnerable systems.

recomended-action-logoRecommended Actions

Upgrade to the latest version, available from the website.
http://www.squid-cache.org/Advisories/SQUID-2016_9.txt

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Detail
2023-05-23 23.560 Sig Added