quid is a web proxy cache. Starting in version 3.5.27 and prior to version 6.8, Squid may be vulnerable to a Denial of Service attack against HTTP Chunked decoder due to an uncontrolled recursion bug. This problem allows a remote attacker to cause Denial of Service when sending a crafted, chunked, encoded HTTP Message. This bug is fixed in Squid version 6.8. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. There is no workaround for this issue.
03 Nov 2025, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
26 Feb 2025, 15:14
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:squid-cache:squid:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:bluexp:-:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* |
|
| References | () http://www.squid-cache.org/Versions/v6/SQUID-2024_1.patch - Mailing List, Patch | |
| References | () https://github.com/squid-cache/squid/security/advisories/GHSA-72c2-c3wm-8qxc - Vendor Advisory | |
| References | () https://lists.fedoraproject.org/archives/list/[email protected]/message/7R4KPSO3MQT3KAOZV7LC2GG3CYMCGK7H/ - Mailing List | |
| References | () https://lists.fedoraproject.org/archives/list/[email protected]/message/XWQHRDRHDM5PQTU6BHH4C5KGL37X6TVI/ - Mailing List | |
| References | () https://security.netapp.com/advisory/ntap-20240605-0001/ - Third Party Advisory | |
| First Time |
Fedoraproject fedora
Squid-cache Squid-cache squid Netapp bluexp Fedoraproject Netapp |
21 Nov 2024, 09:00
| Type | Values Removed | Values Added |
|---|---|---|
| References | () http://www.squid-cache.org/Versions/v6/SQUID-2024_1.patch - | |
| References | () https://github.com/squid-cache/squid/security/advisories/GHSA-72c2-c3wm-8qxc - | |
| References | () https://lists.fedoraproject.org/archives/list/[email protected]/message/7R4KPSO3MQT3KAOZV7LC2GG3CYMCGK7H/ - | |
| References | () https://lists.fedoraproject.org/archives/list/[email protected]/message/XWQHRDRHDM5PQTU6BHH4C5KGL37X6TVI/ - | |
| References | () https://security.netapp.com/advisory/ntap-20240605-0001/ - |
10 Jun 2024, 18:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
25 Apr 2024, 06:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Published : 2024-03-06 19:15
Updated : 2025-11-03 21:16
NVD link : CVE-2024-25111
Mitre link : CVE-2024-25111
CVE.ORG link : CVE-2024-25111
JSON object : View
Uncontrolled Recursion