Input validation error in Squid - CVE-2019-12523

 

Input validation error in Squid - CVE-2019-12523

Published: November 22, 2019


Vulnerability identifier: #VU22908
CSH Severity: Medium
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-12523
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass certain security restrictions.

The vulnerability exists due to insufficient validation of user-supplied input when processing URIs. A remote authenticated attacker can add certain characters to the URI, bypass implemented security restrictions and access restricted websites.


Affected software

Squid
Amazon Linux AMI
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
Opensuse
Ubuntu
Fedora
squid (Debian package)
squid3 (Ubuntu package)
squid (Ubuntu package)
libecap
libecap-devel
squid

How to mitigate CVE-2019-12523

Install updates from vendor's website.

Squid - update to 4.9
squid (Debian package) - update to 4.6-1+deb10u2
squid3 (Ubuntu package) - addressed in versions 3.5.12-1ubuntu7.9, 3.5.27-1ubuntu1.4
squid (Ubuntu package) - addressed in versions 3.5.12-1ubuntu7.12, 3.5.12-1ubuntu7.13, 3.5.27-1ubuntu1.7, 3.5.27-1ubuntu1.8, 4.4-1ubuntu2.3, 4.8-1ubuntu2.1
libecap - update to 1.0.1-2
libecap-devel - update to 1.0.1-2
squid - update to 3.5.20-17.46
squid - addressed in versions 4.9-2.fc30, 4.9-2.fc31
squid - update to 4.11-4

External References

Related Security Bulletins