29-Year-Old ‘Squidbleed’ Vulnerability Discovered With the Aid of Claude Mythos Preview
ID: 2cc899c9-959a-5b36-a073-bdfe8baea03d
STIX ID: report--2cc899c9-959a-5b36-a073-bdfe8baea03d
Feed Name: cybersecurityNews.com
Threat Score
Squidbleed is a critical heap-buffer overread in Squid Proxy, present since a 1997 commit, that can read up to ~4KB of adjacent heap memory and leak stale HTTP request data (including Authorization headers and API keys) via a malformed FTP directory listing; the flaw arises from misusing C's strchr on a null terminator, a PoC has been published and a one-line null-check patch has been merged, and administrators are advised to disable FTP proxy support unless required.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
