Wind River Support Network

HomeDefectsLIN9-9369
Fixed

LIN9-9369 : Security Advisory - squid - CVE-2019-18677

Created: Nov 29, 2019    Updated: Jun 3, 2020
Resolved Date: Jun 3, 2020
Found In Version: 9.0.0.1
Fix Version: 9.0.0.25
Severity: Standard
Applicable for: Wind River Linux 9
Component/s: Userspace

Description

An issue was discovered in Squid 3.x and 4.x through 4.8 when the append_domain setting is used (because the appended characters do not properly interact with hostname length restrictions). Due to incorrect message processing, it can inappropriately redirect traffic to origins it should not be delivered to.

CREATE(Triage):(User=admin) [CVE-2019-18677|https://nvd.nist.gov/vuln/detail/CVE-2019-18677]

CVEs


Live chat
Online