ASA-2019-00452 – Squid: Denial of Service issue in HTTP Basic Authentication processing


Allele Security Alert

ASA-2019-00452

Identifier(s)

ASA-2019-00452, CVE-2019-12529, SQUID-2019:1

Title

Denial of Service issue in HTTP Basic Authentication processing

Vendor(s)

The Squid project

Product(s)

Squid

Affected version(s)

Squid 2.x -> 2.7.STABLE9
Squid 3.x -> 3.5.28
Squid 4.x -> 4.7

Fixed version(s)

Squid 4.8

Proof of concept

Unknown

Description

Due to incorrect buffer management Squid is vulnerable to a denial of service attack when processing HTTP Basic Authentication credentials.

Technical details

Unknown

Credits

Jeriko One

Reference(s)

Squid Proxy Cache Security Update Advisory SQUID-2019:2
http://www.squid-cache.org/Advisories/SQUID-2019_2.txt

CVE-2019-12529
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12529

CVE-2019-12529
https://nvd.nist.gov/vuln/detail/CVE-2019-12529

If there is any error in this alert or you wish a comprehensive analysis, let us know.

Last modified: July 18, 2019

We are not responsible for any data loss, device corruption or any other type of issue due to the use of any information mentioned in our security alerts.