feeds.feedburner.com • 7w
Squid Proxy: Analysis of the 'Squidbleed' Memory Leak CVE-2024-28002
CVE-2024-28002, dubbed "Squidbleed," is a high-severity heap over-read vulnerability located within the FTP parser module of the Squid web proxy. Originating from a code implementation in 1997, the flaw allows an attacker or any user capable of routing traffic through the proxy to read beyond intended memory buffer boundaries. This results in the leakage of sensitive, cleartext data from other concurrent users, specifically HTTP request headers, authentication credentials, and session tokens. Immediate patching or disabling the FTP parser is required to mitigate the risk of unauthorized confidentiality breaches.