Logo
vulnerabilityCVE-2025-54574
Name
CVE-2025-54574
Source
NVD ( link)Debian ( link)
Description
Squid is a caching proxy for the Web. In versions 6.3 and below, Squid is vulnerable to a heap buffer overflow and possible remote code execution attack when processing URN due to incorrect buffer management. This has been fixed in version 6.4. To work around this issue, disable URN access permissions.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
squid
Exploitable

Vulnerability Ratings#


9.3
CVSSv31
9.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
6.14
Not Affected
buildroot
master
7.6
Not Affected
openwrt
master
7.1-r1
Not Affected
openwrt
openwrt-25.12
7.1-r1
Not Affected
yocto
master
7.5
Not Affected
yocto
scarthgap
6.14
Not Affected