CVE-2019-12529
Summary
| CVE | CVE-2019-12529 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-07-11 19:15:00 UTC |
| Updated | 2023-11-07 03:03:00 UTC |
| Description | An issue was discovered in Squid 2.x through 2.7.STABLE9, 3.x through 3.5.28, and 4.x through 4.7. When Squid is configured to use Basic Authentication, the Proxy-Authorization header is parsed via uudecode. uudecode determines how many bytes will be decoded by iterating over the input and checking its table. The length is then used to start decoding the string. There are no checks to ensure that the length it calculates isn't greater than the input buffer. This leads to adjacent memory being decoded as well. An attacker would not be able to retrieve the decoded data unless the Squid maintainer had configured the display of usernames on error pages. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| www.squid-cache.org/Versions/v4/changesets/squid-4-dd46b5417809647f561d8a5e0e74c3... |
CONFIRM |
www.squid-cache.org |
Patch, Vendor Advisory |
| [SECURITY] [DLA 2278-1] squid3 security update |
MLIST |
lists.debian.org |
|
| USN-4065-2: Squid vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
|
| USN-4065-1: Squid vulnerabilities | Ubuntu security notices |
UBUNTU |
usn.ubuntu.com |
|
| [SECURITY] Fedora 29 Update: squid-4.8-2.fc29 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| [SECURITY] [DLA 1858-1] squid3 security update |
MLIST |
lists.debian.org |
|
| [SECURITY] Fedora 29 Update: squid-4.8-2.fc29 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Commits · squid-cache/squid · GitHub |
CONFIRM |
github.com |
Patch, Third Party Advisory |
| [security-announce] openSUSE-SU-2019:2540-1: important: Security update |
SUSE |
lists.opensuse.org |
|
| Bugtraq: [SECURITY] [DSA 4507-1] squid security update |
BUGTRAQ |
seclists.org |
|
| [security-announce] openSUSE-SU-2019:2541-1: important: Security update |
SUSE |
lists.opensuse.org |
|
| Debian -- Security Information -- DSA-4507-1 squid |
DEBIAN |
www.debian.org |
|
| Squid 4 changes |
CONFIRM |
www.squid-cache.org |
Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159658 Oracle Enterprise Linux Security Update for squid:4 (ELSA-2020-4743)
- 296079 Oracle Solaris 11.4 Support Repository Update (SRU) 15.5.0 Missing (CPUOCT2019)
- 356430 Amazon Linux Security Advisory for squid : ALAS2-2023-2318
- 377360 Alibaba Cloud Linux Security Update for squid:4 (ALINUX3-SA-2022:0124)
- 940034 AlmaLinux Security Update for squid:4 (ALSA-2020:4743)
- 960867 Rocky Linux Security Update for squid:4 (RLSA-2020:4743)