Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-47729

Опубликовано: 16 июл. 2026
Источник: debian
EPSS Низкий

Описание

Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in the FTP gateway (src/clients/FtpGateway.cc), Squid is vulnerable to an out-of-bounds read: when a listing entry date in the TypeA or TypeB directory-listing formats is not followed by a filename, parsing was not restricted to the input buffer, so a trusted client accessing a misbehaving FTP server through Squid's gateway feature could read memory from random unrelated transactions. This issue is fixed in version 7.6.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
squidfixed7.6-1package

Примечания

  • https://www.openwall.com/lists/oss-security/2026/06/12/1

  • https://blog.calif.io/p/squidbleed-cve-2026-47729

  • Fixed by: https://github.com/squid-cache/squid/commit/865a131c7d557e68c965043d98c2eccae26deef8 (SQUID_7_6)

  • https://github.com/squid-cache/squid/security/advisories/GHSA-8c37-pxjq-qwrg

EPSS

Процентиль: 72%
0.01503
Низкий

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 2 месяцев назад

Out-of-bounds Read attack against the FTP gateway

CVSS3: 6.5
redhat
около 1 месяца назад

Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in the FTP gateway (src/clients/FtpGateway.cc), Squid is vulnerable to an out-of-bounds read: when a listing entry date in the TypeA or TypeB directory-listing formats is not followed by a filename, parsing was not restricted to the input buffer, so a trusted client accessing a misbehaving FTP server through Squid's gateway feature could read memory from random unrelated transactions. This issue is fixed in version 7.6.

CVSS3: 6.5
nvd
17 дней назад

Squid is a caching proxy for the Web. Prior to 7.6, due to an improper validation of syntactic correctness of input in the FTP gateway (src/clients/FtpGateway.cc), Squid is vulnerable to an out-of-bounds read: when a listing entry date in the TypeA or TypeB directory-listing formats is not followed by a filename, parsing was not restricted to the input buffer, so a trusted client accessing a misbehaving FTP server through Squid's gateway feature could read memory from random unrelated transactions. This issue is fixed in version 7.6.

CVSS3: 6.5
msrc
15 дней назад

Squid: Memory disclosure in FTP gateway

CVSS3: 6.5
fstec
4 месяца назад

Уязвимость функции strchr() прокси-сервера Squid, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 72%
0.01503
Низкий