PT-2019-5184 · Squid+7 · Squid+8

Jeriko One

+1

·

Published

2019-11-14

·

Updated

2023-03-03

·

CVE-2019-18676

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Squid versions 3.x through 4.8
Description An issue was discovered due to incorrect input validation, resulting in a heap-based buffer overflow that can cause Denial of Service to all clients using the proxy. The severity is high because this issue occurs before normal security checks, allowing any remote client that can reach the proxy port to perform the attack via a crafted URI scheme.
Recommendations For Squid versions 3.x through 4.8, update to a version later than 4.8 to resolve the issue. As a temporary workaround, consider restricting access to the proxy port to minimize the risk of exploitation.

Fix

DoS

Memory Corruption

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2020:4743
ALT-PU-2020-1479
ALT-PU-2020-1494
BDU:2020-01857
CESA-2020_4743
CVE-2019-18676
DLA-2278-1
DSA-4682-1
MGASA-2019-0382
OPENSUSE-SU-2019:2540-1
OPENSUSE-SU-2019:2541-1
OPENSUSE-SU-2019_2540-1
OPENSUSE-SU-2019_2541-1
RHSA-2020:4743
RHSA-2020_4743
RLSA-2020:4743
SUSE-SU-2019:2975-1
SUSE-SU-2019:3067-1
SUSE-SU-2020:0661-1
SUSE-SU-2020:14460-1
SUSE-SU-2022:14908-1
SUSE-SU-2022_14908-1
USN-4213-1
USN-4446-1
USN-4446-2

Affected Products

Alt Linux
Almalinux
Centos
Red Hat
Rocky Linux
Squid
Squid Cache
Suse
Ubuntu