Search CVE reports


Toggle filters

51 – 60 of 109 results


CVE-2019-12527

Medium priority

Some fixes available 1 of 2

An issue was discovered in Squid 4.0.23 through 4.7. When checking Basic Authentication with HttpHeader::getAuth, Squid uses a global buffer to store the decoded data. Squid does not check that the decoded length isn't greater...

2 affected packages

squid, squid3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
squid Not in release
squid3 Not affected
Show less packages

CVE-2019-12526

Medium priority
Fixed

An issue was discovered in Squid before 4.9. URN response handling in Squid suffers from a heap-based buffer overflow. When receiving data from a remote server in response to an URN request, Squid fails to ensure that the response...

2 affected packages

squid, squid3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
squid Fixed Not in release
squid3 Not in release Fixed
Show less packages

CVE-2019-12525

Medium priority

Some fixes available 3 of 4

An issue was discovered in Squid 3.3.9 through 3.5.28 and 4.x through 4.7. When Squid is configured to use Digest authentication, it parses the header Proxy-Authorization. It searches for certain tokens such as domain, uri, and...

2 affected packages

squid, squid3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
squid Not in release
squid3 Fixed
Show less packages

CVE-2019-12524

Medium priority
Fixed

An issue was discovered in Squid through 4.7. When handling requests from users, Squid checks its rules to see if the request should be denied. Squid by default comes with rules to block access to the Cache Manager, which serves...

2 affected packages

squid, squid3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
squid Not affected Not in release
squid3 Not in release Fixed
Show less packages

CVE-2019-12523

Medium priority
Fixed

An issue was discovered in Squid before 4.9. When handling a URN request, a corresponding HTTP request is made. This HTTP request doesn't go through the access checks that incoming HTTP requests go through. This causes all access...

2 affected packages

squid, squid3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
squid Fixed Not in release
squid3 Not in release Fixed
Show less packages

CVE-2019-12522

Low priority
Vulnerable

An issue was discovered in Squid through 4.7. When Squid is run as root, it spawns its child processes as a lesser user, by default the user nobody. This is done via the leave_suid call. leave_suid leaves the Saved UID as 0. This...

2 affected packages

squid, squid3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
squid Vulnerable Vulnerable Vulnerable Not in release
squid3 Not in release Not in release Not in release Vulnerable
Show less packages

CVE-2019-12521

Medium priority
Fixed

An issue was discovered in Squid through 4.7. When Squid is parsing ESI, it keeps the ESI elements in ESIContext. ESIContext contains a buffer for holding a stack of ESIElements. When a new ESIElement is parsed, it is added via...

2 affected packages

squid, squid3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
squid Fixed Not in release
squid3 Not in release Fixed
Show less packages

CVE-2019-12520

Medium priority
Fixed

An issue was discovered in Squid through 4.7 and 5. When receiving a request, Squid checks its cache to see if it can serve up a response. It does this by making a MD5 hash of the absolute URL of the request. If found, it servers...

2 affected packages

squid, squid3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
squid Not affected Not in release
squid3 Not in release Fixed
Show less packages

CVE-2019-12519

Medium priority
Fixed

An issue was discovered in Squid through 4.7. When handling the tag esi:when when ESI is enabled, Squid calls ESIExpression::Evaluate. This function uses a fixed stack buffer to hold the expression while it's being evaluated. When...

2 affected packages

squid, squid3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
squid Fixed Not in release
squid3 Not in release Fixed
Show less packages

CVE-2018-19132

Low priority

Some fixes available 2 of 3

Squid before 4.4, when SNMP is enabled, allows a denial of service (Memory Leak) via an SNMP packet.

2 affected packages

squid, squid3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
squid Not in release
squid3 Fixed
Show less packages