Количество 30
Количество 30

CVE-2019-12525
An issue was discovered in Squid 3.3.9 through 3.5.28 and 4.x through 4.7. When Squid is configured to use Digest authentication, it parses the header Proxy-Authorization. It searches for certain tokens such as domain, uri, and qop. Squid checks if this token's value starts with a quote and ends with one. If so, it performs a memcpy of its length minus 2. Squid never checks whether the value is just a single quote (which would satisfy its requirements), leading to a memcpy of its length minus 1.
CVE-2019-12525
An issue was discovered in Squid 3.3.9 through 3.5.28 and 4.x through ...
GHSA-wxh3-97xf-wv5x
An issue was discovered in Squid 3.3.9 through 3.5.28 and 4.x through 4.7. When Squid is configured to use Digest authentication, it parses the header Proxy-Authorization. It searches for certain tokens such as domain, uri, and qop. Squid checks if this token's value starts with a quote and ends with one. If so, it performs a memcpy of its length minus 2. Squid never checks whether the value is just a single quote (which would satisfy its requirements), leading to a memcpy of its length minus 1.
GHSA-82gh-fr9f-867h
An issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resources that are otherwise forbidden. This occurs because the attacker can overflow the nonce reference counter (a short integer). Remote code execution may occur if the pooled token credentials are freed (instead of replayed as valid credentials).

BDU:2021-01723
Уязвимость механизма хранения nonce дайджест-аутентификации прокси-сервера Squid, связанная с целочисленным переполнением значения, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

BDU:2020-02395
Уязвимость компонента Proxy-Authentication прокси-сервера Squid, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код

SUSE-SU-2019:2089-1
Security update for squid

openSUSE-SU-2019:2541-1
Security update for squid

openSUSE-SU-2019:2540-1
Security update for squid

SUSE-SU-2019:2975-1
Security update for squid
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2019-12525 An issue was discovered in Squid 3.3.9 through 3.5.28 and 4.x through 4.7. When Squid is configured to use Digest authentication, it parses the header Proxy-Authorization. It searches for certain tokens such as domain, uri, and qop. Squid checks if this token's value starts with a quote and ends with one. If so, it performs a memcpy of its length minus 2. Squid never checks whether the value is just a single quote (which would satisfy its requirements), leading to a memcpy of its length minus 1. | CVSS3: 9.8 | 61% Средний | почти 6 лет назад |
CVE-2019-12525 An issue was discovered in Squid 3.3.9 through 3.5.28 and 4.x through ... | CVSS3: 9.8 | 61% Средний | почти 6 лет назад | |
GHSA-wxh3-97xf-wv5x An issue was discovered in Squid 3.3.9 through 3.5.28 and 4.x through 4.7. When Squid is configured to use Digest authentication, it parses the header Proxy-Authorization. It searches for certain tokens such as domain, uri, and qop. Squid checks if this token's value starts with a quote and ends with one. If so, it performs a memcpy of its length minus 2. Squid never checks whether the value is just a single quote (which would satisfy its requirements), leading to a memcpy of its length minus 1. | CVSS3: 9.8 | 61% Средний | около 3 лет назад | |
GHSA-82gh-fr9f-867h An issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resources that are otherwise forbidden. This occurs because the attacker can overflow the nonce reference counter (a short integer). Remote code execution may occur if the pooled token credentials are freed (instead of replayed as valid credentials). | 34% Средний | около 3 лет назад | ||
![]() | BDU:2021-01723 Уязвимость механизма хранения nonce дайджест-аутентификации прокси-сервера Squid, связанная с целочисленным переполнением значения, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании | CVSS3: 9.8 | 34% Средний | около 5 лет назад |
![]() | BDU:2020-02395 Уязвимость компонента Proxy-Authentication прокси-сервера Squid, позволяющая нарушителю вызвать отказ в обслуживании или выполнить произвольный код | CVSS3: 9.8 | 61% Средний | почти 6 лет назад |
![]() | SUSE-SU-2019:2089-1 Security update for squid | почти 6 лет назад | ||
![]() | openSUSE-SU-2019:2541-1 Security update for squid | больше 5 лет назад | ||
![]() | openSUSE-SU-2019:2540-1 Security update for squid | больше 5 лет назад | ||
![]() | SUSE-SU-2019:2975-1 Security update for squid | больше 5 лет назад |
Уязвимостей на страницу