
Cloud Vulnerability DB
A community-led vulnerabilities database
An issue was discovered in Squid through version 4.7 affecting the Edge Side Includes (ESI) functionality. When handling the 'esi:when' tag with ESI enabled, Squid calls ESIExpression::Evaluate function which uses a fixed stack buffer to hold expressions during evaluation. The vulnerability exists because there is no check to ensure the stack won't overflow when adding new members during expression processing (NVD, OSS Security).
The vulnerability has been assigned a CVSS v3.1 base score of 9.8 (CRITICAL) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The issue specifically occurs in the ESIExpression::Evaluate function where a fixed stack buffer is used without proper bounds checking. When processing expressions, the function either evaluates the top of the stack or adds new members, but lacks overflow protection mechanisms (NetApp Security).
The vulnerability can lead to multiple severe impacts including cache poisoning, remote code execution, and denial of service. On systems with heap overflow protection, the overflow will cause the proxy to shutdown, resulting in denial of service for all clients. On systems with ESI buffer pooling (the default configuration), the overflow will truncate portions of generated payloads, potentially poisoning the HTTP response cache with corrupted objects. Additionally, the vulnerability allows attackers to overwrite arbitrary attacker-controlled information onto the process stack, enabling remote code execution with specially crafted ESI payloads (OSS Security).
The vulnerability requires an attacker to control an upstream server or compromise the transmission channel to deliver malicious ESI response syntax. The attack vector is network-accessible with low attack complexity, requiring no privileges or user interaction (NVD).
The vulnerability has been fixed in Squid versions 4.11 and 5.0.2. For systems that cannot immediately update, a workaround is available by building Squid with the '--disable-esi' configuration option to disable ESI functionality. Various Linux distributions have also released security updates including Ubuntu, Debian, and OpenSUSE (Ubuntu Security, Debian Security, OpenSUSE Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."