6.1

CVE-2019-18677

An issue was discovered in Squid 3.x and 4.x through 4.8 when the append_domain setting is used (because the appended characters do not properly interact with hostname length restrictions). Due to incorrect message processing, it can inappropriately redirect traffic to origins it should not be delivered to.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Squid-cache ≫ Squid Version >= 2.0 <= 2.7
Squid-cache ≫ Squid Version >= 3.0 <= 3.5.28
Squid-cache ≫ Squid Version >= 4.0 <= 4.8
Squid-cache ≫ Squid Version 2.7 Update stable2
Squid-cache ≫ Squid Version 2.7 Update stable3
Squid-cache ≫ Squid Version 2.7 Update stable4
Squid-cache ≫ Squid Version 2.7 Update stable5
Squid-cache ≫ Squid Version 2.7 Update stable6
Squid-cache ≫ Squid Version 2.7 Update stable7
Squid-cache ≫ Squid Version 2.7 Update stable8
Squid-cache ≫ Squid Version 2.7 Update stable9
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 19.04
Canonical ≫ Ubuntu Linux Version 19.10
Fedoraproject ≫ Fedora Version 30
Fedoraproject ≫ Fedora Version 31
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 7.24% 0.935
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
NIST 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

https://lists.debian.org/debian-lts-announce/2020/07/msg00009.html
https://usn.ubuntu.com/4213-1/
Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MTM74TU2BSLT5B3H4F3UDW53672NVLMC/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UEMOYTMCCFWK5NOXSXEIH5D2VGWVXR67/
https://www.debian.org/security/2020/dsa-4682
https://lists.debian.org/debian-lts-announce/2019/12/msg00011.html
Third Party Advisory
http://www.squid-cache.org/Advisories/SQUID-2019_9.txt
Third Party Advisory
http://www.squid-cache.org/Versions/v3/3.5/changesets/squid-3.5-e5f1813a674848dde570f7920873e1071f96e0b4.patch
Release Notes
http://www.squid-cache.org/Versions/v4/changesets/squid-4-36492033ea4097821a4f7ff3ddcb971fbd1e8ba0.patch
Release Notes
https://bugzilla.suse.com/show_bug.cgi?id=1156328
Third Party Advisory
Issue Tracking
https://github.com/squid-cache/squid/pull/427
Patch
Third Party Advisory