Squid-cache

Squid

106 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.57%
  • Veröffentlicht 15.04.2020 19:15:12
  • Zuletzt bearbeitet 21.11.2024 04:23:01

An issue was discovered in Squid through 4.7. When Squid is parsing ESI, it keeps the ESI elements in ESIContext. ESIContext contains a buffer for holding a stack of ESIElements. When a new ESIElement is parsed, it is added via addStackElement. addSt...

  • EPSS 0.18%
  • Veröffentlicht 15.04.2020 19:15:12
  • Zuletzt bearbeitet 21.11.2024 04:23:01

An issue was discovered in Squid through 4.7. When Squid is run as root, it spawns its child processes as a lesser user, by default the user nobody. This is done via the leave_suid call. leave_suid leaves the Saved UID as 0. This makes it trivial for...

  • EPSS 0.55%
  • Veröffentlicht 15.04.2020 19:15:12
  • Zuletzt bearbeitet 21.11.2024 04:23:02

An issue was discovered in Squid through 4.7. When handling requests from users, Squid checks its rules to see if the request should be denied. Squid by default comes with rules to block access to the Cache Manager, which serves detailed server infor...

  • EPSS 3.44%
  • Veröffentlicht 20.03.2020 21:15:16
  • Zuletzt bearbeitet 05.11.2025 17:15:33

Squid before 4.9, when certain web browsers are used, mishandles HTML in the host (aka hostname) parameter to cachemgr.cgi.

  • EPSS 20.52%
  • Veröffentlicht 04.02.2020 21:15:10
  • Zuletzt bearbeitet 21.11.2024 04:23:02

An issue was discovered in Squid before 4.10. It allows a crafted FTP server to trigger disclosure of sensitive information from heap memory, such as information associated with other users' sessions or non-Squid processes.

  • EPSS 3.29%
  • Veröffentlicht 04.02.2020 20:15:14
  • Zuletzt bearbeitet 21.11.2024 05:38:52

An issue was discovered in Squid before 4.10. Due to incorrect input validation, it can interpret crafted HTTP requests in unexpected ways to access server resources prohibited by earlier security filters.

  • EPSS 43.09%
  • Veröffentlicht 04.02.2020 20:15:14
  • Zuletzt bearbeitet 21.11.2024 05:38:52

An issue was discovered in Squid before 4.10. Due to incorrect buffer management, a remote client can cause a buffer overflow in a Squid instance acting as a reverse proxy.

  • EPSS 0.83%
  • Veröffentlicht 04.02.2020 20:15:14
  • Zuletzt bearbeitet 21.11.2024 05:38:59

An issue was discovered in Squid before 4.10. Due to incorrect input validation, the NTLM authentication credentials parser in ext_lm_group_acl may write to memory outside the credentials buffer. On systems with memory access protections, this can re...

  • EPSS 38.43%
  • Veröffentlicht 26.11.2019 17:15:13
  • Zuletzt bearbeitet 21.11.2024 04:33:31

An issue was discovered in Squid 2.x, 3.x, and 4.x through 4.8. Due to incorrect data management, it is vulnerable to information disclosure when processing HTTP Digest Authentication. Nonce tokens contain the raw byte value of a pointer that sits wi...

  • EPSS 1.37%
  • Veröffentlicht 26.11.2019 17:15:12
  • Zuletzt bearbeitet 21.11.2024 04:33:30

An issue was discovered in Squid 3.x and 4.x through 4.8. Due to incorrect input validation, there is a heap-based buffer overflow that can result in Denial of Service to all clients using the proxy. Severity is high due to this vulnerability occurri...