[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249461

 
 

909

 
 

195508

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Squid: heap-based buffer overflow in HttpHeader::getAuth - CVE-2019-12527

ID: oval:org.secpod.oval:def:58219Date: (C)2019-10-09   (M)2023-11-13
Class: VULNERABILITYFamily: unix




An issue was discovered in Squid 4.0.23 through 4.7. When checking Basic Authentication with HttpHeader::getAuth, Squid uses a global buffer to store the decoded data. Squid does not check that the decoded length isn't greater than the buffer, leading to a heap-based buffer overflow with user controlled data.

Platform:
Red Hat Enterprise Linux 8
Product:
squid
Reference:
CVE-2019-12527
CVE    1
CVE-2019-12527

© SecPod Technologies