Описание
An issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resources that are otherwise forbidden. This occurs because the attacker can overflow the nonce reference counter (a short integer). Remote code execution may occur if the pooled token credentials are freed (instead of replayed as valid credentials).
Релиз | Статус | Примечание |
---|---|---|
bionic | DNE | |
devel | released | 4.10-1ubuntu2 |
eoan | released | 4.8-1ubuntu2.3 |
esm-infra-legacy/trusty | DNE | |
esm-infra/focal | not-affected | 4.10-1ubuntu1.1 |
focal | released | 4.10-1ubuntu1.1 |
groovy | released | 4.10-1ubuntu2 |
hirsute | released | 4.10-1ubuntu2 |
precise/esm | DNE | |
trusty | ignored | end of standard support |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
bionic | released | 3.5.27-1ubuntu1.6 |
devel | DNE | |
eoan | DNE | |
esm-infra-legacy/trusty | DNE | |
esm-infra/bionic | not-affected | 3.5.27-1ubuntu1.6 |
esm-infra/focal | DNE | |
esm-infra/xenial | not-affected | 3.5.12-1ubuntu7.11 |
focal | DNE | |
groovy | DNE | |
hirsute | DNE |
Показывать по
EPSS
7.5 High
CVSS2
9.8 Critical
CVSS3
Связанные уязвимости
An issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resources that are otherwise forbidden. This occurs because the attacker can overflow the nonce reference counter (a short integer). Remote code execution may occur if the pooled token credentials are freed (instead of replayed as valid credentials).
An issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resources that are otherwise forbidden. This occurs because the attacker can overflow the nonce reference counter (a short integer). Remote code execution may occur if the pooled token credentials are freed (instead of replayed as valid credentials).
An issue was discovered in Squid before 5.0.2. A remote attacker can r ...
An issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resources that are otherwise forbidden. This occurs because the attacker can overflow the nonce reference counter (a short integer). Remote code execution may occur if the pooled token credentials are freed (instead of replayed as valid credentials).
Уязвимость механизма хранения nonce дайджест-аутентификации прокси-сервера Squid, связанная с целочисленным переполнением значения, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
EPSS
7.5 High
CVSS2
9.8 Critical
CVSS3