CVE-2020-8517
Summary
| CVE | CVE-2020-8517 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-02-04 20:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | An issue was discovered in Squid before 4.10. Due to incorrect input validation, the NTLM authentication credentials parser in ext_lm_group_acl may write to memory outside the credentials buffer. On systems with memory access protections, this can result in the helper process being terminated unexpectedly. This leads to the Squid process also terminating and a denial of service for all clients using the proxy. |
Risk And Classification
Problem Types: CWE-20 | CWE-787
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Canonical | Ubuntu Linux | 16.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 18.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 19.10 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 16.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 18.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 19.10 | All | All | All |
| Operating System | Opensuse | Leap | 15.1 | All | All | All |
| Operating System | Opensuse | Leap | 15.1 | All | All | All |
| Application | Squid-cache | Squid | All | All | All | All |
| Application | Squid-cache | Squid | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| February 2020 Squid Vulnerabilities in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | Third Party Advisory |
| [security-announce] openSUSE-SU-2020:0623-1: important: Security update | SUSE | lists.opensuse.org | Mailing List, Third Party Advisory |
| Squid: Multiple vulnerabilities (GLSA 202003-34) — Gentoo security | GENTOO | security.gentoo.org | Third Party Advisory |
| www.squid-cache.org/Advisories/SQUID-2020_3.txt | MISC | www.squid-cache.org | Vendor Advisory |
| USN-4289-1: Squid vulnerabilities | Ubuntu security notices | Ubuntu | UBUNTU | usn.ubuntu.com | Third Party Advisory |
| [security-announce] openSUSE-SU-2020:0307-1: moderate: Security update f | SUSE | lists.opensuse.org | Mailing List, Third Party Advisory |
| www.squid-cache.org/Versions/v4/changesets/squid-4-6982f1187a26557e582172965e266f... | MISC | www.squid-cache.org | Patch, Vendor Advisory |
| [security-announce] openSUSE-SU-2020:0606-1: moderate: Security update f | SUSE | lists.opensuse.org | Mailing List, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 296075 Oracle Solaris 11.4 Support Repository Update (SRU) 21.69.0 Missing (CPUAPR2020)
- 355323 Amazon Linux Security Advisory for squid : ALAS2-2023-2062
- 355430 Amazon Linux Security Advisory for squid : ALAS-2023-1766
- 500658 Alpine Linux Security Update for squid
- 504427 Alpine Linux Security Update for squid