CVE 9.3 CRITICAL

Squid’s URN Handling can lead to Buffer Overflow_CVE-2025-54574

9.3 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:H

Description

Squid is a caching proxy for the Web. In versions 6.3 and below, Squid is vulnerable to a heap buffer overflow and possible remote code execution attack when processing URN due to incorrect buffer management. This has been fixed in version 6.4. To work around this issue, disable URN access permissions.

Basic Information

ID CVE-2025-54574
Source GitHub_M
Published Aug 1, 2025 at 18:02
Modified Aug 1, 2025 at 18:43

Affected Product

Vendor squid-cache
Product squid
Version < 6.4
Affected Versions squid-cache squid < 6.4

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.