CVE-2025-54574

EUVD-2025-23392
Squid is a caching proxy for the Web. In versions 6.3 and below, Squid is vulnerable to a heap buffer overflow and possible remote code execution attack when processing URN due to incorrect buffer management. This has been fixed in version 6.4. To work around this issue, disable URN access permissions.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.3 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
Affected Products (NVD)
VendorProductVersion
squid-cachesquid
𝑥
< 6.4
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
squid
focal
Fixed 4.10-1ubuntu1.12
released
jammy
Fixed 5.7-0ubuntu0.22.04.4
released
noble
not-affected
plucky
not-affected
questing
not-affected
resolute
not-affected
squid3
bionic
needs-triage
jammy
dne
noble
dne
plucky
dne
questing
dne
resolute
dne
xenial
needs-triage
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
squid
RHEL 9
7:5.5-6.el9_3.2
fixed