[USN-4213-1] Squid vulnerabilities
Several security issues were fixed in Squid.
Jeriko One and Kristoffer Danielsson discovered that Squid incorrectly
handled certain URN requests. A remote attacker could possibly use this
issue to bypass access checks and access restricted servers. This issue was
only addressed in Ubuntu 19.04 and Ubuntu 19.10. (CVE-2019-12523)
Jeriko One discovered that Squid incorrectly handed URN responses. A remote
attacker could use this issue to cause Squid to crash, resulting in a
denial of service, or possibly execute arbitrary code. (CVE-2019-12526)
Alex Rousskov discovered that Squid incorrectly handled certain strings. A
remote attacker could possibly use this issue to cause Squid to crash,
resulting in a denial of service. This issue only affected Ubuntu 19.04.
(CVE-2019-12854)
Jeriko One and Kristoffer Danielsson discovered that Squid incorrectly
handled certain input. A remote attacker could use this issue to cause
Squid to crash, resulting in a denial of service, or possibly execute
arbitrary code. This issue was only addressed in Ubuntu 19.04 and Ubuntu
19.10. (CVE-2019-18676)
Kristoffer Danielsson discovered that Squid incorrectly handled certain
messages. This issue could result in traffic being redirected to origins
it should not be delivered to. (CVE-2019-18677)
RĂ©gis Leroy discovered that Squid incorrectly handled certain HTTP
request headers. A remote attacker could use this to smuggle HTTP requests
and corrupt caches with arbitrary content. (CVE-2019-18678)
David Fifield discovered that Squid incorrectly handled HTTP Digest
Authentication. A remote attacker could possibly use this issue to obtain
pointer contents and bypass ASLR protections. (CVE-2019-18679)
- ID
- USN-4213-1
- Severity
- medium
- URL
- https://ubuntu.com/security/notices/USN-4213-1
- Published
-
2019-12-04T17:28:48
(4 years ago) - Modified
-
2019-12-04T17:28:48
(4 years ago) - Other Advisories
-
- ALAS-2023-1757
- ALAS-2023-1774
- ALAS2-2020-1486
- ALAS2-2023-2065
- ALAS2-2023-2081
- ALAS2-2023-2318
- ALPINE:CVE-2019-18679
- ALSA-2020:4743
- ASA-201911-8
- DSA-4507-1
- DSA-4682-1
- ELSA-2022-22254
- FEDORA-2019-0b16cbdd0e
- FEDORA-2019-9538783033
- FEDORA-2019-cb50bcc189
- FREEBSD:620685D6-0AA3-11EA-9673-4C72B94353B5
- GLSA-202003-34
- openSUSE-SU-2019:2540-1
- openSUSE-SU-2019:2541-1
- RHSA-2020:4743
- RLSA-2020:4743
- SUSE-SU-2019:2975-1
- SUSE-SU-2019:3067-1
- SUSE-SU-2020:0661-1
- USN-4446-1
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:deb/ubuntu/squidclient?distro=xenial | ubuntu | squidclient | < 3.5.12-1ubuntu7.9 | xenial | ||
Affected | pkg:deb/ubuntu/squidclient?distro=eoan | ubuntu | squidclient | < 4.8-1ubuntu2.1 | eoan | ||
Affected | pkg:deb/ubuntu/squidclient?distro=disco | ubuntu | squidclient | < 4.4-1ubuntu2.3 | disco | ||
Affected | pkg:deb/ubuntu/squidclient?distro=bionic | ubuntu | squidclient | < 3.5.27-1ubuntu1.4 | bionic | ||
Affected | pkg:deb/ubuntu/squid?distro=xenial | ubuntu | squid | < 3.5.12-1ubuntu7.9 | xenial | ||
Affected | pkg:deb/ubuntu/squid?distro=eoan | ubuntu | squid | < 4.8-1ubuntu2.1 | eoan | ||
Affected | pkg:deb/ubuntu/squid?distro=disco | ubuntu | squid | < 4.4-1ubuntu2.3 | disco | ||
Affected | pkg:deb/ubuntu/squid?distro=bionic | ubuntu | squid | < 3.5.27-1ubuntu1.4 | bionic | ||
Affected | pkg:deb/ubuntu/squid3?distro=xenial | ubuntu | squid3 | < 3.5.12-1ubuntu7.9 | xenial | ||
Affected | pkg:deb/ubuntu/squid3?distro=eoan | ubuntu | squid3 | < 4.8-1ubuntu2.1 | eoan | ||
Affected | pkg:deb/ubuntu/squid3?distro=disco | ubuntu | squid3 | < 4.4-1ubuntu2.3 | disco | ||
Affected | pkg:deb/ubuntu/squid3?distro=bionic | ubuntu | squid3 | < 3.5.27-1ubuntu1.4 | bionic | ||
Affected | pkg:deb/ubuntu/squid-purge?distro=xenial | ubuntu | squid-purge | < 3.5.12-1ubuntu7.9 | xenial | ||
Affected | pkg:deb/ubuntu/squid-purge?distro=eoan | ubuntu | squid-purge | < 4.8-1ubuntu2.1 | eoan | ||
Affected | pkg:deb/ubuntu/squid-purge?distro=disco | ubuntu | squid-purge | < 4.4-1ubuntu2.3 | disco | ||
Affected | pkg:deb/ubuntu/squid-purge?distro=bionic | ubuntu | squid-purge | < 3.5.27-1ubuntu1.4 | bionic | ||
Affected | pkg:deb/ubuntu/squid-common?distro=xenial | ubuntu | squid-common | < 3.5.12-1ubuntu7.9 | xenial | ||
Affected | pkg:deb/ubuntu/squid-common?distro=eoan | ubuntu | squid-common | < 4.8-1ubuntu2.1 | eoan | ||
Affected | pkg:deb/ubuntu/squid-common?distro=disco | ubuntu | squid-common | < 4.4-1ubuntu2.3 | disco | ||
Affected | pkg:deb/ubuntu/squid-common?distro=bionic | ubuntu | squid-common | < 3.5.27-1ubuntu1.4 | bionic | ||
Affected | pkg:deb/ubuntu/squid-cgi?distro=xenial | ubuntu | squid-cgi | < 3.5.12-1ubuntu7.9 | xenial | ||
Affected | pkg:deb/ubuntu/squid-cgi?distro=eoan | ubuntu | squid-cgi | < 4.8-1ubuntu2.1 | eoan | ||
Affected | pkg:deb/ubuntu/squid-cgi?distro=disco | ubuntu | squid-cgi | < 4.4-1ubuntu2.3 | disco | ||
Affected | pkg:deb/ubuntu/squid-cgi?distro=bionic | ubuntu | squid-cgi | < 3.5.27-1ubuntu1.4 | bionic |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |