Back

MEDIUM

squid: lack of UID assignment in child process spawning could lead to privileges escalation

Published Apr 15, 2020

Description

An issue was discovered in Squid through 4.7. When Squid is run as root, it spawns its child processes as a lesser user, by default the user nobody. This is done via the leave_suid call. leave_suid leaves the Saved UID as 0. This makes it trivial for an attacker who has compromised the child process to escalate their privileges back to root.

Affected products

Remediation

Red Hat statement

This issue is not a big problem on its own, as it requires another remote code execution vulnerability or that a local user has the privileges to modify the squid processes to be exploited. Thus, it is actually closer to a security enhancement than a vulnerability.

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 15, 2020
Updated Aug 4, 2024
Reserved Jun 2, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Apr 24, 2020
ENISA EUVD
Assigner mitre
Published Apr 15, 2020
Updated Aug 4, 2024
Exploited since n/a
EUVD-2019-4117