Back

HIGH

squid: Buffer Overflow in ext_lm_group_acl helper

Published Feb 4, 2020

Description

An issue was discovered in Squid before 4.10. Due to incorrect input validation, the NTLM authentication credentials parser in ext_lm_group_acl may write to memory outside the credentials buffer. On systems with memory access protections, this can result in the helper process being terminated unexpectedly. This leads to the Squid process also terminating and a denial of service for all clients using the proxy.

Affected products

Remediation

No remediation recorded yet.

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 4, 2020
Updated Aug 4, 2024
Reserved Feb 2, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Feb 2, 2020
ENISA EUVD
Assigner mitre
Published Feb 4, 2020
Updated Aug 4, 2024
Exploited since n/a
EUVD-2020-29383