ISOMAN

CVE

CVE-2020-8449

An issue was discovered in Squid before 4.10. Due to incorrect input validation, it can interpret crafted HTTP requests in unexpected ways to access server resources prohibited by earlier security filters.

Severity
HIGH
CVSS
7.5
Published
Modified

Linked Releases

References

  1. http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00012.html
  2. http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00010.html
  3. http://www.squid-cache.org/Advisories/SQUID-2020_1.txt
  4. http://www.squid-cache.org/Versions/v3/3.5/changesets/SQUID-2020_1.patch
  5. http://www.squid-cache.org/Versions/v3/3.5/changesets/squid-3.5-8e657e835965c3a011375feaa0359921c5b3e2dd.patch
  6. http://www.squid-cache.org/Versions/v4/changesets/SQUID-2020_1.patch
  7. http://www.squid-cache.org/Versions/v4/changesets/squid-4-b3a0719affab099c684f1cd62b79ab02816fa962.patch
  8. http://www.squid-cache.org/Versions/v4/changesets/squid-4-d8e4715992d0e530871519549add5519cbac0598.patch
  9. https://lists.debian.org/debian-lts-announce/2020/07/msg00009.html
  10. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/G6W2IQ7QV2OGREFFUBNVZIDD3RJBDE4R/
  11. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TSU6SPANL27AGK5PCGBJOKG4LUWA555J/
  12. https://security.gentoo.org/glsa/202003-34
  13. https://security.netapp.com/advisory/ntap-20210304-0002/
  14. https://usn.ubuntu.com/4289-1/
  15. https://www.debian.org/security/2020/dsa-4682
  16. http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00012.html
  17. http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00010.html
  18. http://www.squid-cache.org/Advisories/SQUID-2020_1.txt
  19. http://www.squid-cache.org/Versions/v3/3.5/changesets/SQUID-2020_1.patch
  20. http://www.squid-cache.org/Versions/v3/3.5/changesets/squid-3.5-8e657e835965c3a011375feaa0359921c5b3e2dd.patch