QID 198313

Date Published: 2021-04-06

QID 198313: Ubuntu Security Notification for Squid, Squid3 Vulnerabilities (USN-4895-1)

It was discovered that Squid incorrectly handled certain Content-Length headers.

It was discovered that Squid incorrectly validated certain input.

A remote attacker could possibly use this issue to perform an HTTP request smuggling attack, resulting in cache poisoning. This issue only affected Ubuntu 20.04 LTS. (CVE-2020-15049)

A remote attacker could use this issue to perform HTTP Request Smuggling and possibly access services forbidden by the security controls. (CVE-2020-25097)

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.5 severity.
  • Solution
    Refer to Ubuntu advisory USN-4895-1 for affected packages and patching details, or update with your package manager.
    Vendor References

    CVEs related to QID 198313

    Software Advisories
    Advisory ID Software Component Link
    USN-4895-1 16.04 (Xenial) on src squid URL Logo launchpad.net/ubuntu/+source/squid3/3.5.12-1ubuntu7.16
    USN-4895-1 18.04 (bionic) on src squid URL Logo launchpad.net/ubuntu/+source/squid3/3.5.27-1ubuntu1.10
    USN-4895-1 20.04 (focal) on src squid URL Logo launchpad.net/ubuntu/+source/squid/4.10-1ubuntu1.3
    USN-4895-1 20.10 (groovy) on src squid URL Logo launchpad.net/ubuntu/+source/squid/4.13-1ubuntu2.1