ALT-PU-2020-1909-1
Closed vulnerabilities
BDU:2021-01723
Уязвимость механизма хранения nonce дайджест-аутентификации прокси-сервера Squid, связанная с целочисленным переполнением значения, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
BDU:2021-01747
Уязвимость функции ESIExpression:: Evaluate прокси-сервера Squid, связанная с выходом операции за допустимые границы буфера данных, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2019-12519
An issue was discovered in Squid through 4.7. When handling the tag esi:when when ESI is enabled, Squid calls ESIExpression::Evaluate. This function uses a fixed stack buffer to hold the expression while it's being evaluated. When processing the expression, it could either evaluate the top of the stack, or add a new member to the stack. When adding a new member, there is no check to ensure that the stack won't overflow.
- openSUSE-SU-2020:0623
- openSUSE-SU-2020:0623
- [oss-security] 20200423 [ADVISORY] SQUID-2019:12 Multiple issues in ESI Response processing
- [oss-security] 20200423 [ADVISORY] SQUID-2019:12 Multiple issues in ESI Response processing
- https://gitlab.com/jeriko.one/security/-/blob/master/squid/CVEs/CVE-2019-12519.txt
- https://gitlab.com/jeriko.one/security/-/blob/master/squid/CVEs/CVE-2019-12519.txt
- [debian-lts-announce] 20200710 [SECURITY] [DLA 2278-1] squid3 security update
- [debian-lts-announce] 20200710 [SECURITY] [DLA 2278-1] squid3 security update
- GLSA-202005-05
- GLSA-202005-05
- https://security.netapp.com/advisory/ntap-20210205-0006/
- https://security.netapp.com/advisory/ntap-20210205-0006/
- USN-4356-1
- USN-4356-1
- DSA-4682
- DSA-4682
Modified: 2024-11-21
CVE-2020-11945
An issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resources that are otherwise forbidden. This occurs because the attacker can overflow the nonce reference counter (a short integer). Remote code execution may occur if the pooled token credentials are freed (instead of replayed as valid credentials).
- openSUSE-SU-2020:0623
- http://master.squid-cache.org/Versions/v4/changesets/squid-4-eeebf0f37a72a2de08348e85ae34b02c34e9a811.patch
- http://www.openwall.com/lists/oss-security/2020/04/23/2
- http://www.squid-cache.org/Versions/v4/changesets/squid-4-eeebf0f37a72a2de08348e85ae34b02c34e9a811.patch
- https://bugzilla.suse.com/show_bug.cgi?id=1170313
- https://github.com/squid-cache/squid/commit/eeebf0f37a72a2de08348e85ae34b02c34e9a811
- https://github.com/squid-cache/squid/pull/585
- [debian-lts-announce] 20200710 [SECURITY] [DLA 2278-1] squid3 security update
- FEDORA-2020-848065cc4c
- FEDORA-2020-56e809930e
- FEDORA-2020-a6a921a591
- GLSA-202005-05
- https://security.netapp.com/advisory/ntap-20210304-0004/
- USN-4356-1
- DSA-4682
- openSUSE-SU-2020:0623
- DSA-4682
- USN-4356-1
- https://security.netapp.com/advisory/ntap-20210304-0004/
- GLSA-202005-05
- FEDORA-2020-a6a921a591
- FEDORA-2020-56e809930e
- FEDORA-2020-848065cc4c
- [debian-lts-announce] 20200710 [SECURITY] [DLA 2278-1] squid3 security update
- https://github.com/squid-cache/squid/pull/585
- https://github.com/squid-cache/squid/commit/eeebf0f37a72a2de08348e85ae34b02c34e9a811
- https://bugzilla.suse.com/show_bug.cgi?id=1170313
- http://www.squid-cache.org/Versions/v4/changesets/squid-4-eeebf0f37a72a2de08348e85ae34b02c34e9a811.patch
- http://www.openwall.com/lists/oss-security/2020/04/23/2
- http://master.squid-cache.org/Versions/v4/changesets/squid-4-eeebf0f37a72a2de08348e85ae34b02c34e9a811.patch