NULL pointer derefenrece in Squid - CVE-2018-1000024

 

NULL pointer derefenrece in Squid - CVE-2018-1000024

Published: February 6, 2018 / Updated: August 22, 2020


Vulnerability identifier: #VU10383
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1000024
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to incorrect pointer handling when processing ESI responses. A remote attacker can supply a specially crafted response to the vulnerable server and trigger application crash.

Affected software

Squid
Debian Linux
Amazon Linux AMI
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Ubuntu
Fedora
squid3 (Ubuntu package)
squid (Alpine package)
squid (Red Hat package)
squid (Ubuntu package)
squid

How to mitigate CVE-2018-1000024

Install update from vendor's website.

Squid - addressed in versions 3.5.28, 4.0.23
squid3 (Ubuntu package) - update to 3.1.19-1ubuntu3.12.04.9
squid (Alpine package) - update to 3.5.27-r0
squid (Red Hat package) - update to 3.5.20-15.el7
squid (Ubuntu package) - update to Ubuntu Pro (Infra-only)
squid - addressed in versions 4.0.23-1.fc26, 4.0.23-2.fc27

External References

Related Security Bulletins