Your submission was sent successfully! Close

You have successfully unsubscribed! Close

CVE-2020-8450

Published: 4 February 2020

An issue was discovered in Squid before 4.10. Due to incorrect buffer management, a remote client can cause a buffer overflow in a Squid instance acting as a reverse proxy.

Notes

AuthorNote
mdeslaur
same commits as CVE-2020-8449

Priority

Medium

CVSS 3 base score: 7.3

Status

Package Release Status
squid
Launchpad, Ubuntu, Debian
bionic Does not exist

eoan
Released (4.8-1ubuntu2.2)
focal
Released (4.9-2ubuntu4)
groovy
Released (4.9-2ubuntu4)
hirsute
Released (4.9-2ubuntu4)
precise Does not exist

trusty Does not exist

upstream Needs triage

xenial Does not exist

Patches:
upstream: http://www.squid-cache.org/Versions/v4/changesets/SQUID-2020_1.patch (Squid 4.8 and older)
upstream: http://www.squid-cache.org/Versions/v4/changesets/squid-4-b3a0719affab099c684f1cd62b79ab02816fa962.patch (Squid 4.9)

squid3
Launchpad, Ubuntu, Debian
bionic
Released (3.5.27-1ubuntu1.5)
eoan Does not exist

focal Does not exist

groovy Does not exist

hirsute Does not exist

precise Ignored
(end of ESM support, was needs-triage)
trusty Does not exist

upstream Needs triage

xenial
Released (3.5.12-1ubuntu7.10)
Patches:


upstream: http://www.squid-cache.org/Versions/v3/3.5/changesets/SQUID-2020_1.patch