squid: Improper input validation issues in HTTP Request processing
Published Feb 4, 2020
7.5
HIGHCVSS 3.1
EPSS 8.31%
Description
An issue was discovered in Squid before 4.10. Due to incorrect input validation, it can interpret crafted HTTP requests in unexpected ways to access server resources prohibited by earlier security filters.
Affected products
No data.
Configuration 1
- < 4.10
Configuration 2
- 9.0
- 10.0
Configuration 3
- 16.04
- 18.04
- 19.10
Configuration 5
- 30
- 31
No data.
Red Hat Enterprise Linux 7
squid-7:3.5.20-17.el7_9.4
Fixed · RHSA-2020:4082
Red Hat Enterprise Linux 8
squid:4-8030020200828070549.30b713e6
Fixed · RHSA-2020:4743
Red Hat Enterprise Linux 5
squid
Not affected
Red Hat Enterprise Linux 6
squid
Will not fix
Red Hat Enterprise Linux 6
squid34
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | squid-7:3.5.20-17.el7_9.4 | Fixed | RHSA-2020:4082 |
| Red Hat Enterprise Linux 8 | squid:4-8030020200828070549.30b713e6 | Fixed | RHSA-2020:4743 |
| Red Hat Enterprise Linux 5 | squid | Not affected | n/a |
| Red Hat Enterprise Linux 6 | squid | Will not fix | n/a |
| Red Hat Enterprise Linux 6 | squid34 | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This only affects deployments acting as reverse proxy with a http_port 'accel' or 'vhost' (squid 2.x and 3.x) or http_port 'accel' configuration (squid 4.x).
References (19)
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00012.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00010.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://www.squid-cache.org/Advisories/SQUID-2020_1.txt x_refsource_MISCPatchVendor Advisory
- http://www.squid-cache.org/Versions/v3/3.5/changesets/SQUID-2020_1.patch x_refsource_MISCPatchVendor Advisory
- http://www.squid-cache.org/Versions/v3/3.5/changesets/squid-3.5-8e657e835965c3a011375feaa0359921c5b3e2dd.patch x_refsource_MISCPatchVendor Advisory
- http://www.squid-cache.org/Versions/v4/changesets/SQUID-2020_1.patch x_refsource_MISCPatchVendor Advisory
- http://www.squid-cache.org/Versions/v4/changesets/squid-4-b3a0719affab099c684f1cd62b79ab02816fa962.patch x_refsource_MISCPatchVendor Advisory
- http://www.squid-cache.org/Versions/v4/changesets/squid-4-d8e4715992d0e530871519549add5519cbac0598.patch x_refsource_MISCPatchVendor Advisory
- https://access.redhat.com/security/cve/CVE-2020-8449 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1798540 Issue Tracking
- https://lists.debian.org/debian-lts-announce/2020/07/msg00009.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/G6W2IQ7QV2OGREFFUBNVZIDD3RJBDE4R/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TSU6SPANL27AGK5PCGBJOKG4LUWA555J/ vendor-advisoryx_refsource_FEDORA
- https://nvd.nist.gov/vuln/detail/CVE-2020-8449
- https://security.gentoo.org/glsa/202003-34 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://security.netapp.com/advisory/ntap-20210304-0002/ x_refsource_CONFIRMThird Party Advisory
- https://usn.ubuntu.com/4289-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-8449
- https://www.debian.org/security/2020/dsa-4682 vendor-advisoryx_refsource_DEBIANThird Party Advisory
Change history (0)
No recorded changes yet.