Описание
An issue was discovered in Squid before 4.10. It allows a crafted FTP server to trigger disclosure of sensitive information from heap memory, such as information associated with other users' sessions or non-Squid processes.
A flaw was found in squid. It allows a crafted FTP server to trigger disclosure of sensitive information from heap memory, such as information associated with other users' sessions or non-Squid processes.
Меры по смягчению последствий
As a workaround, it is possible to disable support for FTP. In order to do so, remove the following line from your squid configuration file: acl Safe_ports 21 Then add the following lines to your squid configuration file: acl FTP proto FTP http_access deny FTP
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 5 | squid | Out of support scope | ||
Red Hat Enterprise Linux 6 | squid | Out of support scope | ||
Red Hat Enterprise Linux 6 | squid34 | Out of support scope | ||
Red Hat Enterprise Linux 7 | squid | Fixed | RHSA-2020:4082 | 30.09.2020 |
Red Hat Enterprise Linux 8 | squid | Fixed | RHSA-2020:4743 | 04.11.2020 |
Показывать по
Дополнительная информация
Статус:
EPSS
5.9 Medium
CVSS3
Связанные уязвимости
An issue was discovered in Squid before 4.10. It allows a crafted FTP server to trigger disclosure of sensitive information from heap memory, such as information associated with other users' sessions or non-Squid processes.
An issue was discovered in Squid before 4.10. It allows a crafted FTP server to trigger disclosure of sensitive information from heap memory, such as information associated with other users' sessions or non-Squid processes.
An issue was discovered in Squid before 4.10. It allows a crafted FTP ...
An issue was discovered in Squid before 4.10. It allows a crafted FTP server to trigger disclosure of sensitive information from heap memory, such as information associated with other users' sessions or non-Squid processes.
Уязвимость прокси-сервера Squid, связанная с выходом операции за границы буфера в памяти, позволяюшая нарушителю получить доступ к защищаемой информации
EPSS
5.9 Medium
CVSS3