Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Debian 8: DLA-1858-1 High Severity: Squid3 Denial of Service Issue

debian lts
Calendar Grey July 20, 2019
Dist Debian Esm H88
The latest Squid3 revision resolves potential denial of service vulnerabilities linked to buffer management in HTTP auth processes.
Squid, a high-performance proxy caching server for web clients, has been found vulnerable to denial of service attacks associated with HTTP authentication header processing

Summary

CVE-2019-12525

Due to incorrect buffer management Squid is vulnerable to a denial
of service attack when processing HTTP Digest Authentication
credentials.

Due to incorrect input validation the HTTP Request header parser for
Digest authentication may access memory outside the allocated memory
buffer.

On systems with memory access protections this can result in the
Squid process being terminated unexpectedly. Resulting in a denial
of service for all clients using the proxy.

CVE-2019-12529

Due to incorrect buffer management Squid is vulnerable to a denial
of service attack when processing HTTP Basic Authentication
credentials.

Due to incorrect string termination the Basic authentication
credentials decoder may access memory outside the decode buffer.

On systems with memory access protections this can result in the
Squid process being terminated unexpectedly. Resulting in a denial
of service for all clients using the proxy.

Read the Full Advisory


<pre><font face="Courier">Package: squid3
Version: 3.4.8-6+deb8u8
CVE ID: CVE-2019-12525 CVE-2019-12529

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here