CVE-2024-23638

SQUID-2023:11 Denial of Service in Cache Manager

Squid is a caching proxy for the Web. Due to an expired pointer reference bug, Squid prior to version 6.6 is vulnerable to a Denial of Service attack against Cache Manager error responses. This problem allows a trusted client to perform Denial of Service when generating error pages for Client Manager reports. Squid older than 5.0.5 have not been tested and should be assumed to be vulnerable. All Squid-5.x up to and including 5.9 are vulnerable. All Squid-6.x up to and including 6.5 are vulnerable. This bug is fixed by Squid version 6.6. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. As a workaround, prevent access to Cache Manager using Squid's main access control: `http_access deny manager`.


We have discovered 9,992 live websites that are affected by CVE-2024-23638.

Test my site




Affected Software

Product  squid
Category Cache Tools
Vulnerable Domains9,992 live websites (98.51% of squid install base)
Vulnerable Versions
  • from 0 before 6.6
Vulnerable Versions Count62 versions ( 91.18% of all versions)


Common Weakness Enumeration

CWE-825 Expired Pointer Dereference



Details

  • Published - Jan 23, 2024
  • Updated - Feb 13, 2025

CVE-2024-23638 usage by Country

United States1,080 websites



Germany4,338 websites
Japan1,029 websites
GB572 websites
China442 websites
France347 websites
Poland315 websites
Spain278 websites
Czech Republic152 websites
Italy147 websites

CVE-2024-23638 usage by TLD

.de2,742 websites
.com2,619 websites
.co.uk413 websites
.org408 websites
.net377 websites
.fr310 websites
.es231 websites
.pl203 websites
.at179 websites
.jp179 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-23638

Top websites that are affected by CVE-2024-23638. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.*********.net GB*,***
***.org United States*,***
*********.net GB*,***
*****.edu United States*,***
*********.**.uk GB**,***
*****.******.********.edu United States**,***
*****.org France**,***
****.*********.net GB**,***
*****.*****.ca Canada**,***
*******.**.jp United States**,***
See full domain list

FAQ

CVE-2024-23638 is Expired Pointer Dereference in squid
A total of 9,992 websites have been identified as vulnerable to CVE-2024-23638, discovered through global website indexing conducted by WebTechSurvey.
squid is susceptible to CVE-2024-23638 vulnerability.
squid versions before 6.6 are vulnerable to CVE-2024-23638.
Version 6.6 of squid addresses the CVE-2024-23638 security vulnerability.