Squid is a caching proxy for the Web. Prior to version 7.5, due to heap Use-After-Free, Squid is vulnerable to Denial of Service when handling ICP traffic. This problem allows a remote attacker to perform a reliable and repeatable Denial of Service attack against the Squid service using ICP protocol. This attack is limited to Squid deployments that explicitly enable ICP support (i.e. configure non-zero `icp_port`). This problem _cannot_ be mitigated by denying ICP queries using `icp_access` rules. Version 7.5 contains a patch.
| Vendor | Product | Versions |
|---|---|---|
| Squid | Squid | 3.5.28, 4.17, 5.9, 6.14, 7.4 |
Updated severity to HIGH, added CVSS estimate of 7.5, and marked exploit as available and actively exploited.
Added vendor and product information, updated affected versions, changed severity to HIGH, and marked exploit as available and actively exploited.
Initial creation