[USN-4356-1] Squid vulnerabilities

Severity Medium
Affected Packages 23
CVEs 4

Several security issues were fixed in Squid.

Jeriko One discovered that Squid incorrectly handled certain Edge Side
Includes (ESI) responses. A malicious remote server could cause Squid to
crash, possibly poison the cache, or possibly execute arbitrary code.
(CVE-2019-12519, CVE-2019-12521)

It was discovered that Squid incorrectly handled the hostname parameter to
cachemgr.cgi when certain browsers are used. A remote attacker could
possibly use this issue to inject HTML or invalid characters in the
hostname parameter. This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04
LTS, and Ubuntu 19.10. (CVE-2019-18860)

Clément Berthaux and Florian Guilbert discovered that Squid incorrectly
handled Digest Authentication nonce values. A remote attacker could
use this issue to replay nonce values, or possibly execute arbitrary code.
(CVE-2020-11945)

Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:deb/ubuntu/squidclient?distro=xenial ubuntu squidclient < 3.5.12-1ubuntu7.11 xenial
Affected pkg:deb/ubuntu/squidclient?distro=focal ubuntu squidclient < 4.10-1ubuntu1.1 focal
Affected pkg:deb/ubuntu/squidclient?distro=eoan ubuntu squidclient < 4.8-1ubuntu2.3 eoan
Affected pkg:deb/ubuntu/squidclient?distro=bionic ubuntu squidclient < 3.5.27-1ubuntu1.6 bionic
Affected pkg:deb/ubuntu/squid?distro=xenial ubuntu squid < 3.5.12-1ubuntu7.11 xenial
Affected pkg:deb/ubuntu/squid?distro=focal ubuntu squid < 4.10-1ubuntu1.1 focal
Affected pkg:deb/ubuntu/squid?distro=eoan ubuntu squid < 4.8-1ubuntu2.3 eoan
Affected pkg:deb/ubuntu/squid?distro=bionic ubuntu squid < 3.5.27-1ubuntu1.6 bionic
Affected pkg:deb/ubuntu/squid3?distro=xenial ubuntu squid3 < 3.5.12-1ubuntu7.11 xenial
Affected pkg:deb/ubuntu/squid3?distro=eoan ubuntu squid3 < 4.8-1ubuntu2.3 eoan
Affected pkg:deb/ubuntu/squid3?distro=bionic ubuntu squid3 < 3.5.27-1ubuntu1.6 bionic
Affected pkg:deb/ubuntu/squid-purge?distro=xenial ubuntu squid-purge < 3.5.12-1ubuntu7.11 xenial
Affected pkg:deb/ubuntu/squid-purge?distro=focal ubuntu squid-purge < 4.10-1ubuntu1.1 focal
Affected pkg:deb/ubuntu/squid-purge?distro=eoan ubuntu squid-purge < 4.8-1ubuntu2.3 eoan
Affected pkg:deb/ubuntu/squid-purge?distro=bionic ubuntu squid-purge < 3.5.27-1ubuntu1.6 bionic
Affected pkg:deb/ubuntu/squid-common?distro=xenial ubuntu squid-common < 3.5.12-1ubuntu7.11 xenial
Affected pkg:deb/ubuntu/squid-common?distro=focal ubuntu squid-common < 4.10-1ubuntu1.1 focal
Affected pkg:deb/ubuntu/squid-common?distro=eoan ubuntu squid-common < 4.8-1ubuntu2.3 eoan
Affected pkg:deb/ubuntu/squid-common?distro=bionic ubuntu squid-common < 3.5.27-1ubuntu1.6 bionic
Affected pkg:deb/ubuntu/squid-cgi?distro=xenial ubuntu squid-cgi < 3.5.12-1ubuntu7.11 xenial
Affected pkg:deb/ubuntu/squid-cgi?distro=focal ubuntu squid-cgi < 4.10-1ubuntu1.1 focal
Affected pkg:deb/ubuntu/squid-cgi?distro=eoan ubuntu squid-cgi < 4.8-1ubuntu2.3 eoan
Affected pkg:deb/ubuntu/squid-cgi?distro=bionic ubuntu squid-cgi < 3.5.27-1ubuntu1.6 bionic
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...