Squid is a caching proxy for the Web. Prior to version 7.5, due to premature release of resource during expected lifetime and heap Use-After-Free bugs, Squid is vulnerable to Denial of Service when handling ICP traffic. This problem allows a remote attacker to perform a reliable and repeatable Denial of Service attack against the Squid service using ICP protocol. This attack is limited to Squid deployments that explicitly enable ICP support (i.e. configure non-zero icp_port). This problem cannot be mitigated by denying ICP queries using icp_access rules. This bug is fixed in Squid version 7.5.
{
"binaries": [
{
"binary_name": "squid",
"binary_version": "5.9-0ubuntu0.22.04.4"
},
{
"binary_name": "squid-cgi",
"binary_version": "5.9-0ubuntu0.22.04.4"
},
{
"binary_name": "squid-common",
"binary_version": "5.9-0ubuntu0.22.04.4"
},
{
"binary_name": "squid-openssl",
"binary_version": "5.9-0ubuntu0.22.04.4"
},
{
"binary_name": "squid-purge",
"binary_version": "5.9-0ubuntu0.22.04.4"
},
{
"binary_name": "squidclient",
"binary_version": "5.9-0ubuntu0.22.04.4"
}
]
}{
"binaries": [
{
"binary_name": "squid",
"binary_version": "6.14-0ubuntu0.24.04.1"
},
{
"binary_name": "squid-cgi",
"binary_version": "6.14-0ubuntu0.24.04.1"
},
{
"binary_name": "squid-common",
"binary_version": "6.14-0ubuntu0.24.04.1"
},
{
"binary_name": "squid-openssl",
"binary_version": "6.14-0ubuntu0.24.04.1"
},
{
"binary_name": "squid-purge",
"binary_version": "6.14-0ubuntu0.24.04.1"
},
{
"binary_name": "squidclient",
"binary_version": "6.14-0ubuntu0.24.04.1"
}
]
}{
"binaries": [
{
"binary_name": "squid",
"binary_version": "6.14-0ubuntu0.25.10.1"
},
{
"binary_name": "squid-cgi",
"binary_version": "6.14-0ubuntu0.25.10.1"
},
{
"binary_name": "squid-common",
"binary_version": "6.14-0ubuntu0.25.10.1"
},
{
"binary_name": "squid-openssl",
"binary_version": "6.14-0ubuntu0.25.10.1"
},
{
"binary_name": "squid-purge",
"binary_version": "6.14-0ubuntu0.25.10.1"
},
{
"binary_name": "squidclient",
"binary_version": "6.14-0ubuntu0.25.10.1"
}
]
}{
"binaries": [
{
"binary_name": "squid",
"binary_version": "3.5.12-1ubuntu7.16+esm6"
},
{
"binary_name": "squid-cgi",
"binary_version": "3.5.12-1ubuntu7.16+esm6"
},
{
"binary_name": "squid-common",
"binary_version": "3.5.12-1ubuntu7.16+esm6"
},
{
"binary_name": "squid-purge",
"binary_version": "3.5.12-1ubuntu7.16+esm6"
},
{
"binary_name": "squid3",
"binary_version": "3.5.12-1ubuntu7.16+esm6"
},
{
"binary_name": "squidclient",
"binary_version": "3.5.12-1ubuntu7.16+esm6"
}
]
}{
"binaries": [
{
"binary_name": "squid",
"binary_version": "3.5.27-1ubuntu1.14+esm5"
},
{
"binary_name": "squid-cgi",
"binary_version": "3.5.27-1ubuntu1.14+esm5"
},
{
"binary_name": "squid-common",
"binary_version": "3.5.27-1ubuntu1.14+esm5"
},
{
"binary_name": "squid-purge",
"binary_version": "3.5.27-1ubuntu1.14+esm5"
},
{
"binary_name": "squid3",
"binary_version": "3.5.27-1ubuntu1.14+esm5"
},
{
"binary_name": "squidclient",
"binary_version": "3.5.27-1ubuntu1.14+esm5"
}
]
}{
"binaries": [
{
"binary_name": "squid",
"binary_version": "4.10-1ubuntu1.13+esm2"
},
{
"binary_name": "squid-cgi",
"binary_version": "4.10-1ubuntu1.13+esm2"
},
{
"binary_name": "squid-common",
"binary_version": "4.10-1ubuntu1.13+esm2"
},
{
"binary_name": "squid-purge",
"binary_version": "4.10-1ubuntu1.13+esm2"
},
{
"binary_name": "squidclient",
"binary_version": "4.10-1ubuntu1.13+esm2"
}
]
}