Allele Security Alert
ASA-2019-00454
Identifier(s)
ASA-2019-00454, CVE-2019-12527, SQUID-2019:5
Title
Heap overflow issue in HTTP Basic Authentication processing
Vendor(s)
The Squid project
Product(s)
Squid
Affected version(s)
Squid 4.0.23 -> 4.7
Fixed version(s)
Squid 4.8
Proof of concept
Unknown
Description
Due to incorrect buffer management Squid is vulnerable to a heap overflow and possible remote code execution attack when processing HTTP Authentication credentials.
Technical details
Unknown
Credits
Jeriko One
Reference(s)
Squid Proxy Cache Security Update Advisory SQUID-2019:3
http://www.squid-cache.org/Advisories/SQUID-2019_3.txt
CVE-2019-12527
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-12527
CVE-2019-12527
https://nvd.nist.gov/vuln/detail/CVE-2019-12527
If there is any error in this alert or you wish a comprehensive analysis, let us know.
Last modified: July 19, 2019