squid: Buffer Overflow in ext_lm_group_acl helper
Published Feb 4, 2020
8.1
HIGHCVSS 3.1
EPSS 6.85%
Description
An issue was discovered in Squid before 4.10. Due to incorrect input validation, the NTLM authentication credentials parser in ext_lm_group_acl may write to memory outside the credentials buffer. On systems with memory access protections, this can result in the helper process being terminated unexpectedly. This leads to the Squid process also terminating and a denial of service for all clients using the proxy.
Affected products
No data.
Configuration 1
- < 4.10
Configuration 3
- 16.04
- 18.04
- 19.10
No data.
Red Hat Enterprise Linux 5
squid
Not affected
Red Hat Enterprise Linux 6
squid
Not affected
Red Hat Enterprise Linux 6
squid34
Not affected
Red Hat Enterprise Linux 7
squid
Not affected
Red Hat Enterprise Linux 8
squid:4/squid
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | squid | Not affected | n/a |
| Red Hat Enterprise Linux 6 | squid | Not affected | n/a |
| Red Hat Enterprise Linux 6 | squid34 | Not affected | n/a |
| Red Hat Enterprise Linux 7 | squid | Not affected | n/a |
| Red Hat Enterprise Linux 8 | squid:4/squid | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (13)
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00012.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00010.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00018.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://www.squid-cache.org/Advisories/SQUID-2020_3.txt x_refsource_MISCVendor Advisory
- http://www.squid-cache.org/Versions/v4/changesets/squid-4-6982f1187a26557e582172965e266f544ea562a5.patch x_refsource_MISCPatchVendor Advisory
- https://access.redhat.com/security/cve/CVE-2020-8517 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1798545 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-29383 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-8517
- https://security.gentoo.org/glsa/202003-34 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://security.netapp.com/advisory/ntap-20210304-0002/ x_refsource_CONFIRMThird Party Advisory
- https://usn.ubuntu.com/4289-1/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-8517
Change history (0)
No recorded changes yet.