Логотип exploitDog
bind:CVE-2020-11945
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2020-11945

Количество 14

Количество 14

ubuntu логотип

CVE-2020-11945

около 5 лет назад

An issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resources that are otherwise forbidden. This occurs because the attacker can overflow the nonce reference counter (a short integer). Remote code execution may occur if the pooled token credentials are freed (instead of replayed as valid credentials).

CVSS3: 9.8
EPSS: Средний
redhat логотип

CVE-2020-11945

около 5 лет назад

An issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resources that are otherwise forbidden. This occurs because the attacker can overflow the nonce reference counter (a short integer). Remote code execution may occur if the pooled token credentials are freed (instead of replayed as valid credentials).

CVSS3: 8.1
EPSS: Средний
nvd логотип

CVE-2020-11945

около 5 лет назад

An issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resources that are otherwise forbidden. This occurs because the attacker can overflow the nonce reference counter (a short integer). Remote code execution may occur if the pooled token credentials are freed (instead of replayed as valid credentials).

CVSS3: 9.8
EPSS: Средний
debian логотип

CVE-2020-11945

около 5 лет назад

An issue was discovered in Squid before 5.0.2. A remote attacker can r ...

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-82gh-fr9f-867h

около 3 лет назад

An issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resources that are otherwise forbidden. This occurs because the attacker can overflow the nonce reference counter (a short integer). Remote code execution may occur if the pooled token credentials are freed (instead of replayed as valid credentials).

EPSS: Средний
fstec логотип

BDU:2021-01723

около 5 лет назад

Уязвимость механизма хранения nonce дайджест-аутентификации прокси-сервера Squid, связанная с целочисленным переполнением значения, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

CVSS3: 9.8
EPSS: Средний
rocky логотип

RLSA-2020:2041

около 5 лет назад

Important: squid:4 security update

EPSS: Низкий
oracle-oval логотип

ELSA-2020-2041

около 5 лет назад

ELSA-2020-2041: squid:4 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2020-2040

около 5 лет назад

ELSA-2020-2040: squid security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:1227-1

около 5 лет назад

Security update for squid

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2020:0623-1

около 5 лет назад

Security update for squid

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:1156-1

около 5 лет назад

Security update for squid

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:1134-1

около 5 лет назад

Security update for squid

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:14460-1

почти 5 лет назад

Security update for squid3

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2020-11945

An issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resources that are otherwise forbidden. This occurs because the attacker can overflow the nonce reference counter (a short integer). Remote code execution may occur if the pooled token credentials are freed (instead of replayed as valid credentials).

CVSS3: 9.8
34%
Средний
около 5 лет назад
redhat логотип
CVE-2020-11945

An issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resources that are otherwise forbidden. This occurs because the attacker can overflow the nonce reference counter (a short integer). Remote code execution may occur if the pooled token credentials are freed (instead of replayed as valid credentials).

CVSS3: 8.1
34%
Средний
около 5 лет назад
nvd логотип
CVE-2020-11945

An issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resources that are otherwise forbidden. This occurs because the attacker can overflow the nonce reference counter (a short integer). Remote code execution may occur if the pooled token credentials are freed (instead of replayed as valid credentials).

CVSS3: 9.8
34%
Средний
около 5 лет назад
debian логотип
CVE-2020-11945

An issue was discovered in Squid before 5.0.2. A remote attacker can r ...

CVSS3: 9.8
34%
Средний
около 5 лет назад
github логотип
GHSA-82gh-fr9f-867h

An issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resources that are otherwise forbidden. This occurs because the attacker can overflow the nonce reference counter (a short integer). Remote code execution may occur if the pooled token credentials are freed (instead of replayed as valid credentials).

34%
Средний
около 3 лет назад
fstec логотип
BDU:2021-01723

Уязвимость механизма хранения nonce дайджест-аутентификации прокси-сервера Squid, связанная с целочисленным переполнением значения, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании

CVSS3: 9.8
34%
Средний
около 5 лет назад
rocky логотип
RLSA-2020:2041

Important: squid:4 security update

около 5 лет назад
oracle-oval логотип
ELSA-2020-2041

ELSA-2020-2041: squid:4 security update (IMPORTANT)

около 5 лет назад
oracle-oval логотип
ELSA-2020-2040

ELSA-2020-2040: squid security update (IMPORTANT)

около 5 лет назад
suse-cvrf логотип
SUSE-SU-2020:1227-1

Security update for squid

около 5 лет назад
suse-cvrf логотип
openSUSE-SU-2020:0623-1

Security update for squid

около 5 лет назад
suse-cvrf логотип
SUSE-SU-2020:1156-1

Security update for squid

около 5 лет назад
suse-cvrf логотип
SUSE-SU-2020:1134-1

Security update for squid

около 5 лет назад
suse-cvrf логотип
SUSE-SU-2020:14460-1

Security update for squid3

почти 5 лет назад

Уязвимостей на страницу