PT-2020-5786 · Squid+8 · Squid+9
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Squid versions through 4.7
Description:
The issue is related to the ESIExpression::Evaluate function in the Squid proxy server, which is associated with a buffer data boundary overflow. This could allow a remote attacker to access confidential data, compromise its integrity, and cause a denial of service. The problem arises when handling the
esi:when tag with ESI enabled, as the ESIExpression::Evaluate function uses a fixed stack buffer without checking for potential overflows when adding new members to the stack.Recommendations:
For Squid versions through 4.7, consider disabling the ESI feature to prevent exploitation until a patch is available.
As a temporary workaround, restrict access to the
ESIExpression::Evaluate function to minimize the risk of exploitation.
Avoid using the esi:when tag in configurations where ESI is enabled until the issue is resolved.Fix
DoS
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Almalinux
Centos
Linuxmint
Red Hat
Rocky Linux
Squid
Squid Cache
Suse
Ubuntu