Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2020-8517
Description:An issue was discovered in Squid before 4.10. Due to incorrect input validation, the NTLM authentication credentials parser in ext_lm_group_acl may write to memory outside the credentials buffer. On systems with memory access protections, this can result in the helper process being terminated unexpectedly. This leads to the Squid process also terminating and a denial of service for all clients using the proxy.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2020-8517
https://security.gentoo.org/glsa/202003-34
http://www.squid-cache.org/Advisories/SQUID-2020_3.txt
http://www.squid-cache.org/Versions/v4/changesets/squid-4-6982f1187a26557e582172965e266f544ea562a5.patch
SuSE Security Announcement: openSUSE-SU-2020:0307 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00012.html
SuSE Security Announcement: openSUSE-SU-2020:0606 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00010.html
SuSE Security Announcement: openSUSE-SU-2020:0623 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00018.html
https://usn.ubuntu.com/4289-1/




© 1998-2025 E-Soft Inc. All rights reserved.