Wind River Support Network

HomeDefectsLIN8-12493
Fixed

LIN8-12493 : Security Advisory - squid - CVE-2018-1000027

Created: May 31, 2020    Updated: Jul 1, 2020
Resolved Date: Jun 23, 2020
Previous ID: LIN10-7372
Found In Version: 8.0.0.33
Fix Version: 8.0.0.34
Severity: Standard
Applicable for: Wind River Linux 8
Component/s: Userspace

Description

The Squid Software Foundation Squid HTTP Caching Proxy version prior to version 4.0.23 contains a NULL Pointer Dereference vulnerability in HTTP Response X-Forwarded-For header processing that can result in Denial of Service to all clients of the proxy. This attack appear to be exploitable via Remote HTTP server responding with an X-Forwarded-For header to certain types of HTTP request. This vulnerability appears to have been fixed in 4.0.23 and later.

CREATE(Triage):(User=admin) [CVE-2018-1000027|https://nvd.nist.gov/vuln/detail/CVE-2018-1000027]

CVEs


Live chat
Online