An issue was discovered in Squid 4.0.23 through 4.7. When checking Basic Authentication with HttpHeader::getAuth, Squid uses a global buffer to store the decoded data. Squid does not check that the decoded length isn't greater than the buffer, leading to a heap-based buffer overflow with user controlled data.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade libecap-develUpgrade libecap | May 13, 2022 | Jul 11, 2019 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jul 11, 2019 |
| Centos_linux | — | Upgrade squidUpgrade libecap-debuginfoUpgrade libecap-develUpgrade libecap-debugsourceUpgrade squid-debuginfoUpgrade libecapUpgrade squid-debugsource | Sep 3, 2019 | Jul 11, 2019 |
| Debian | — | Upgrade squid | Oct 22, 2019 | Jul 11, 2019 |
| Huawei Euleros 2_0_sp8 | — | Upgrade squid | Sep 30, 2019 | Jul 11, 2019 |
| Oracle Solaris | — | Upgrade web/proxy/squid to version 4.8-11.4.15.0.1.3.0 on Solaris 11.4 | Nov 20, 2019 | Jul 11, 2019 |
| Oracle_linux | — | Upgrade libecapUpgrade squidUpgrade libecap-devel | Jul 21, 2020 | Jul 12, 2019 |
| Redhat_linux | — | Upgrade libecapUpgrade libecap-debugsourceUpgrade squid-debuginfoUpgrade libecap-debuginfoUpgrade squidUpgrade squid-debugsourceUpgrade libecap-devel | Sep 3, 2019 | Jul 11, 2019 |
| Rocky_linux | — | Upgrade libecap-develUpgrade libecap-debuginfoUpgrade libecapUpgrade libecap-debugsource | Mar 12, 2024 | Jul 11, 2019 |
| Suse | — | Upgrade squid | Nov 22, 2019 | Jul 11, 2019 |
| Ubuntu | — | Upgrade squid | Jul 19, 2019 | Jul 11, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub