PT-2019-5184 · Squid+7 · Squid+8
Jeriko One
+1
·
Published
2019-11-14
·
Updated
2023-03-03
·
CVE-2019-18676
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Squid versions 3.x through 4.8
Description
An issue was discovered due to incorrect input validation, resulting in a heap-based buffer overflow that can cause Denial of Service to all clients using the proxy. The severity is high because this issue occurs before normal security checks, allowing any remote client that can reach the proxy port to perform the attack via a crafted URI scheme.
Recommendations
For Squid versions 3.x through 4.8, update to a version later than 4.8 to resolve the issue.
As a temporary workaround, consider restricting access to the proxy port to minimize the risk of exploitation.
Fix
DoS
Memory Corruption
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Centos
Red Hat
Rocky Linux
Squid
Squid Cache
Suse
Ubuntu