Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-8450

Опубликовано: 03 фев. 2020
Источник: redhat
CVSS3: 5.9
EPSS Средний

Описание

An issue was discovered in Squid before 4.10. Due to incorrect buffer management, a remote client can cause a buffer overflow in a Squid instance acting as a reverse proxy.

A flaw was found in squid. Due to incorrect buffer management, a remote client can cause a buffer overflow in a Squid instance acting as a reverse proxy.

Отчет

Although the squid packages for Red Hat Enterprise Linux 6 through 8 are affected, they are compiled with FORTIFY_SOURCE, which in this case limits the impact of the buffer overflow to an application termination. This only affects deployments acting as reverse proxy with a http_port 'accel' or 'vhost' (squid 2.x and 3.x) or http_port 'accel' configuration (squid 4.x).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5squidNot affected
Red Hat Enterprise Linux 6squidWill not fix
Red Hat Enterprise Linux 6squid34Out of support scope
Red Hat Enterprise Linux 7squidFixedRHSA-2020:408230.09.2020
Red Hat Enterprise Linux 8squidFixedRHSA-2020:474304.11.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=1798552squid: Buffer overflow in reverse-proxy configurations

EPSS

Процентиль: 97%
0.40592
Средний

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.3
ubuntu
больше 5 лет назад

An issue was discovered in Squid before 4.10. Due to incorrect buffer management, a remote client can cause a buffer overflow in a Squid instance acting as a reverse proxy.

CVSS3: 7.3
nvd
больше 5 лет назад

An issue was discovered in Squid before 4.10. Due to incorrect buffer management, a remote client can cause a buffer overflow in a Squid instance acting as a reverse proxy.

CVSS3: 7.3
debian
больше 5 лет назад

An issue was discovered in Squid before 4.10. Due to incorrect buffer ...

github
около 3 лет назад

An issue was discovered in Squid before 4.10. Due to incorrect buffer management, a remote client can cause a buffer overflow in a Squid instance acting as a reverse proxy.

CVSS3: 7.3
fstec
больше 5 лет назад

Уязвимость прокси-сервера Squid, вызванная переполнением буфера, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 97%
0.40592
Средний

5.9 Medium

CVSS3