The Squid proxy server has identified 55 vulnerabilities, 35 of which are still unpatched.

The results of an independent security audit of the open caching proxy server Squid, conducted in 2021, have been published. During the inspection of the project's codebase, 55 vulnerabilities were identified, of which 35 issues remain unaddressed by the developers (0-day). Squid's developers were notified of the problems two and a half years ago but have yet to complete work on their resolution. Ultimately, the audit author decided to disclose the information without waiting for all issues to be fixed and informed Squid's developers in advance.

Among the identified vulnerabilities:

  • Stack overflow in the hash-based authentication implementation (Digest Authentication), occurring when processing the HTTP header Proxy-Authorization with an excessively large value for the 'Digest nc' field.
  • Use-after-free in the TRACE method request handler.
  • Use-after-free when processing HTTP requests with the 'Range' header (CVE-2021-31807).
  • Stack overflow when processing the X-Forwarded-For HTTP header.
  • Stack overflow when handling chunked requests.
  • Use-after-free in the CacheManager web interface.
  • Integer overflow in the Range HTTP header handler (CVE-2021-31808).
  • Use-after-free and buffer overflow in the ESI (Edge Side Includes) expression handler.
  • Numerous memory leaks, buffer overflows when reading, and issues leading to crashes.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster