Squid Caching Proxy Security Audit: 55 vulnerabilities and 35 0days
megamansec.github.io
megamansec.github.io
That is probably why they have not been fixed. The best solution is to drop support for these technologies from squid altogether, rather than someone waste precious time fixing them.
However, from the top 5:
Chunked Encoding Stack Overflow
X-Forwarded-For Stack Overflow
Cache Poisoning by Large Stored Response Headers (With Bonus XSS)
all pertain to issues affecting practically every single Squid instance.Except perhaps FTP but I believe squid must be configured to allow FTP proxying anyway
This is specifically mentioned, for example https://megamansec.github.io/Squid-Security-Audit/ftp-assert...: A reproducer is given base64-encoded. (Note: This does NOT require Squid to even be enabled to proxy FTP links, and even with the configuration acl ftp proto FTP http_access deny ftp this crash will occur).
This is exactly how organizations and larger software distributions get stuck on outdated versions of software packages. They are using some feature in the software to glue things together or something, the package drops that support, and they get stuck because they can't make a massive software upgrade happen quickly, or some aspect of that interface is outside their control.
I have seen this so much that its not even something that surprises me. I am not even surprised about the other side of the argument that seems to assume that you can just burn a ton of code or even a ton of hardware just because its no longer the style in vogue these days. And then these people wonder why companies that make 50 year guarantees of software compatibility like IBM are so popular.