7.5

CVE-2020-8449

An issue was discovered in Squid before 4.10. Due to incorrect input validation, it can interpret crafted HTTP requests in unexpected ways to access server resources prohibited by earlier security filters.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Squid-cache ≫ Squid Version < 4.10
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 19.10
Opensuse ≫ Leap Version 15.1
Fedoraproject ≫ Fedora Version 30
Fedoraproject ≫ Fedora Version 31
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 8.31% 0.942
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-668 Exposure of Resource to Wrong Sphere

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

https://lists.debian.org/debian-lts-announce/2020/07/msg00009.html
Third Party Advisory
Mailing List
https://www.debian.org/security/2020/dsa-4682
Third Party Advisory
https://security.gentoo.org/glsa/202003-34
Third Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00012.html
Third Party Advisory
Mailing List
http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00010.html
Third Party Advisory
Mailing List
http://www.squid-cache.org/Advisories/SQUID-2020_1.txt
Patch
Vendor Advisory
http://www.squid-cache.org/Versions/v3/3.5/changesets/SQUID-2020_1.patch
Patch
Vendor Advisory
http://www.squid-cache.org/Versions/v3/3.5/changesets/squid-3.5-8e657e835965c3a011375feaa0359921c5b3e2dd.patch
Patch
Vendor Advisory
http://www.squid-cache.org/Versions/v4/changesets/SQUID-2020_1.patch
Patch
Vendor Advisory
http://www.squid-cache.org/Versions/v4/changesets/squid-4-b3a0719affab099c684f1cd62b79ab02816fa962.patch
Patch
Vendor Advisory
http://www.squid-cache.org/Versions/v4/changesets/squid-4-d8e4715992d0e530871519549add5519cbac0598.patch
Patch
Vendor Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/G6W2IQ7QV2OGREFFUBNVZIDD3RJBDE4R/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TSU6SPANL27AGK5PCGBJOKG4LUWA555J/
https://security.netapp.com/advisory/ntap-20210304-0002/
Third Party Advisory
https://usn.ubuntu.com/4289-1/
Third Party Advisory