Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.142633
Category:Web Servers
Title:Squid Security Update Advisory (SQUID-2019:5)
Summary:Squid is prone to a heap overflow vulnerability due to incorrect buffer; management when processing HTTP Authentication credentials.
Description:Summary:
Squid is prone to a heap overflow vulnerability due to incorrect buffer
management when processing HTTP Authentication credentials.

Vulnerability Insight:
This allows a malicious client to write a substantial amount of arbitrary data
to the heap. Potentially gaining ability to execute arbitrary code.

On systems with memory access protections this can result in the Squid process being terminated unexpectedly.
Resulting in a denial of service for all clients using the proxy.

This issue is limited to traffic accessing the Squid Cache Manager reports or using the FTP protocol gateway.

Affected Software/OS:
Squid versions 4.0.23 through 4.7.

Solution:
Update to version 4.8 or later.

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2019-12527
BugTraq ID: 109143
http://www.securityfocus.com/bid/109143
Bugtraq: 20190825 [SECURITY] [DSA 4507-1] squid security update (Google Search)
https://seclists.org/bugtraq/2019/Aug/42
Debian Security Information: DSA-4507 (Google Search)
https://www.debian.org/security/2019/dsa-4507
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SPXN2CLAGN5QSQBTOV5IGVLDOQSRFNTZ/
RedHat Security Advisories: RHSA-2019:2593
https://access.redhat.com/errata/RHSA-2019:2593
SuSE Security Announcement: openSUSE-SU-2019:2540 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00053.html
SuSE Security Announcement: openSUSE-SU-2019:2541 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00056.html
https://usn.ubuntu.com/4065-1/
CopyrightCopyright (C) 2019 Greenbone Networks GmbH

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.