Denial of service in Squid - CVE-2018-1000027

 

Denial of service in Squid - CVE-2018-1000027

Published: February 6, 2018 / Updated: February 6, 2018


Vulnerability identifier: #VU10384
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-1000027
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists due to unspecified error. A remote attacker can cause denial of service issue in HTTP Message processing.

Affected software

Squid
Debian Linux
Amazon Linux AMI
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Workstation
Ubuntu
Fedora
squid3 (Ubuntu package)
squid (Red Hat package)
squid (Alpine package)
squid (Ubuntu package)
squid

How to mitigate CVE-2018-1000027

Install update from vendor's website.

squid3 (Ubuntu package) - update to 3.1.19-1ubuntu3.12.04.9
squid (Red Hat package) - update to 3.5.20-15.el7
squid (Alpine package) - update to 3.5.27-r0
squid (Ubuntu package) - update to Ubuntu Pro (Infra-only)
squid - addressed in versions 4.0.23-1.fc26, 4.0.23-2.fc27

External References

Related Security Bulletins