Bug 2294353 (CVE-2024-37894) - CVE-2024-37894 squid: Out-of-bounds write error may lead to Denial of Service
Summary: CVE-2024-37894 squid: Out-of-bounds write error may lead to Denial of Service
Keywords:
Status: NEW
Alias: CVE-2024-37894
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2294354 2294355 2294356
Blocks: 2294352
TreeView+ depends on / blocked
 
Reported: 2024-06-26 01:09 UTC by Patrick Del Bello
Modified: 2024-10-10 13:50 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2024:4914 0 None None None 2024-07-30 11:23:42 UTC
Red Hat Product Errata RHSA-2024:4861 0 None None None 2024-07-25 08:37:06 UTC
Red Hat Product Errata RHSA-2024:5906 0 None None None 2024-08-27 18:27:31 UTC

Description Patrick Del Bello 2024-06-26 01:09:36 UTC
Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to an Out-of-bounds Write error when assigning ESI variables, Squid is susceptible to a Memory Corruption error. This error can lead to a Denial of Service attack.

References:
https://github.com/squid-cache/squid/security/advisories/GHSA-wgvf-q977-9xjg
https://megamansec.github.io/Squid-Security-Audit/esi-underflow.html

Upstream patch:
https://github.com/squid-cache/squid/commit/f411fe7d75197852f0e5ee85027a06d58dd8df4c.patch

Comment 1 Patrick Del Bello 2024-06-26 01:12:40 UTC
Created clustal-omega tracking bugs for this issue:

Affects: epel-7 [bug 2294355]
Affects: fedora-all [bug 2294356]


Created squid tracking bugs for this issue:

Affects: fedora-all [bug 2294354]

Comment 3 errata-xmlrpc 2024-07-25 08:37:06 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2024:4861 https://access.redhat.com/errata/RHSA-2024:4861

Comment 4 errata-xmlrpc 2024-08-27 18:27:30 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Extended Update Support

Via RHSA-2024:5906 https://access.redhat.com/errata/RHSA-2024:5906


Note You need to log in before you can comment on or make changes to this bug.