Mythos discovers 'Squidbleed,' a memory leak that's gone undetected since Clinton era

https://image.theregister.com/5260387.jpg?imageId=5260387&x=0&y=0&cropw=100&croph=100&panox=0&panoy=0&panow=100&panoh=100&width=1200&height=683

Plus more blasts from the past: NetWare, FTP, and HTTP

Sometimes it takes a while to detect a vuln. A 29-year-old, Heartbleed-style vulnerability in Squid, a popular open-source caching proxy server, silently leaked users' plaintext HTTP requests and potentially revealed sensitive data, including credentials and session tokens, for decades - until AI (and a few humans) saved the day.

A security researcher and Mythos Preview found the flaw and reported it to project maintainers, who fixed the code earlier this month.

Squid is widely used by large corporations, schools, and internet service providers to cache, filter, and monitor network traffic, and Calif.io researcher Lam Jun Rong said he came across the open source proxy while attempting to connect to the internet on a flight.

“As you might expect, the version of Squid deployed on that plane was released nearly 10 years ago and is affected by the vulnerability I'm about...

Copyright of this story solely belongs to theregister.com. To see the full text click HERE

Read more