Описание
An issue was discovered in Squid before 4.12 and 5.x before 5.0.3. Due to use of a potentially dangerous function, Squid and the default certificate validation helper are vulnerable to a Denial of Service when opening a TLS connection to an attacker-controlled server for HTTPS. This occurs because unrecognized error values are mapped to NULL, but later code expects that each error value is mapped to a valid error string.
Релиз | Статус | Примечание |
---|---|---|
bionic | DNE | |
devel | not-affected | code not compiled |
eoan | not-affected | code not compiled |
esm-infra-legacy/trusty | DNE | |
esm-infra/focal | not-affected | code not compiled |
focal | not-affected | code not compiled |
precise/esm | DNE | |
trusty | ignored | end of standard support |
trusty/esm | DNE | |
upstream | needs-triage |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
bionic | not-affected | code not compiled |
devel | DNE | |
eoan | DNE | |
esm-infra-legacy/trusty | DNE | |
esm-infra/bionic | not-affected | code not compiled |
esm-infra/focal | DNE | |
esm-infra/xenial | not-affected | code not compiled |
focal | DNE | |
precise/esm | not-affected | code not compiled |
trusty | ignored | end of standard support |
Показывать по
Ссылки на источники
EPSS
5 Medium
CVSS2
7.5 High
CVSS3
Связанные уязвимости
An issue was discovered in Squid before 4.12 and 5.x before 5.0.3. Due to use of a potentially dangerous function, Squid and the default certificate validation helper are vulnerable to a Denial of Service when opening a TLS connection to an attacker-controlled server for HTTPS. This occurs because unrecognized error values are mapped to NULL, but later code expects that each error value is mapped to a valid error string.
An issue was discovered in Squid before 4.12 and 5.x before 5.0.3. Due to use of a potentially dangerous function, Squid and the default certificate validation helper are vulnerable to a Denial of Service when opening a TLS connection to an attacker-controlled server for HTTPS. This occurs because unrecognized error values are mapped to NULL, but later code expects that each error value is mapped to a valid error string.
An issue was discovered in Squid before 4.12 and 5.x before 5.0.3. Due ...
ELSA-2020-4743: squid:4 security, bug fix, and enhancement update (MODERATE)
EPSS
5 Medium
CVSS2
7.5 High
CVSS3