CVE-2019-12523
Summary
| CVE | CVE-2019-12523 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-11-26 17:15:00 UTC |
| Updated | 2023-11-07 03:03:00 UTC |
| Description | An issue was discovered in Squid before 4.9. When handling a URN request, a corresponding HTTP request is made. This HTTP request doesn't go through the access checks that incoming HTTP requests go through. This causes all access checks to be bypassed and allows access to restricted HTTP servers, e.g., an attacker can connect to HTTP servers that only listen on localhost. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Canonical | Ubuntu Linux | 16.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 16.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 18.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 19.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 19.10 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 16.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 18.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 19.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 19.10 | All | All | All |
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Operating System | Fedoraproject | Fedora | 30 | All | All | All |
| Operating System | Fedoraproject | Fedora | 31 | All | All | All |
| Operating System | Fedoraproject | Fedora | 30 | All | All | All |
| Operating System | Fedoraproject | Fedora | 31 | All | All | All |
| Operating System | Opensuse | Leap | 15.0 | All | All | All |
| Operating System | Opensuse | Leap | 15.0 | All | All | All |
| Application | Squid-cache | Squid | All | All | All | All |
| Application | Squid-cache | Squid | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SECURITY] [DLA 2278-1] squid3 security update | MLIST | lists.debian.org | |
| [security-announce] openSUSE-SU-2019:2541-1: important: Security update | CONFIRM | lists.opensuse.org | Mailing List, Third Party Advisory |
| [SECURITY] Fedora 30 Update: squid-4.9-2.fc30 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | Mailing List, Third Party Advisory |
| USN-4446-1: Squid vulnerabilities | Ubuntu security notices | Ubuntu | UBUNTU | usn.ubuntu.com | |
| USN-4213-1: Squid vulnerabilities | Ubuntu security notices | Ubuntu | UBUNTU | usn.ubuntu.com | Third Party Advisory |
| [SECURITY] Fedora 31 Update: squid-4.9-2.fc31 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 31 Update: squid-4.9-2.fc31 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | Mailing List, Third Party Advisory |
| Debian -- Security Information -- DSA-4682-1 squid | DEBIAN | www.debian.org | |
| [SECURITY] Fedora 30 Update: squid-4.9-2.fc30 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| Bug 1156329 – VUL-0: CVE-2019-12523,CVE-2019-18676: squid,squid3: improper input validation can lead to access to restricted HTTP servers or denial of service | CONFIRM | bugzilla.suse.com | Issue Tracking, Third Party Advisory |
| www.squid-cache.org/Advisories/SQUID-2019_8.txt | CONFIRM | www.squid-cache.org | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159658 Oracle Enterprise Linux Security Update for squid:4 (ELSA-2020-4743)
- 160118 Oracle Enterprise Linux Security Update for squid (ELSA-2022-22254)
- 296075 Oracle Solaris 11.4 Support Repository Update (SRU) 21.69.0 Missing (CPUAPR2020)
- 355319 Amazon Linux Security Advisory for squid : ALAS2-2023-2065
- 355348 Amazon Linux Security Advisory for squid : ALAS-2023-1757
- 356277 Amazon Linux Security Advisory for squid : ALASSQUID4-2023-007
- 377360 Alibaba Cloud Linux Security Update for squid:4 (ALINUX3-SA-2022:0124)
- 670223 EulerOS Security Update for squid (EulerOS-SA-2021-1852)
- 753154 SUSE Enterprise Linux Security Update for squid (SUSE-SU-2022:14908-1)
- 940034 AlmaLinux Security Update for squid:4 (ALSA-2020:4743)
- 960867 Rocky Linux Security Update for squid:4 (RLSA-2020:4743)