CVE-2019-12527
published 2019-07-11CVE-2019-12527: An issue was discovered in Squid 4.0.23 through 4.7. When checking Basic Authentication with HttpHeader::getAuth, Squid uses a global buffer to store the…
PriorityP265high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
49.04%
98.8th percentile
An issue was discovered in Squid 4.0.23 through 4.7. When checking Basic Authentication with HttpHeader::getAuth, Squid uses a global buffer to store the decoded data. Squid does not check that the decoded length isn't greater than the buffer, leading to a heap-based buffer overflow with user controlled data.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | squid | < squid 4.8-1 (bookworm) | squid 4.8-1 (bookworm) |
| fedoraproject | fedora | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
| squid-cache | squid | 4.0.23 – 4.7 | — |
| squid | squid | >= 0 < 4.8-1 | 4.8-1 |
| squid | squid | >= 0 < 4.8-1 | 4.8-1 |
| squid | squid | >= 0 < 4.8-1 | 4.8-1 |
| squid | squid | >= 0 < 4.8-1 | 4.8-1 |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability is triggered via Basic Authentication headers — monitor for oversized or malformed Base64-encoded Authorization: Basic headers sent to Squid proxy (versions 4.0.23 through 4.7), which cause a heap-based buffer overflow in HttpHeader::getAuth. ↗
- →Apply ACL-based mitigation by denying FTP protocol URLs being proxied and Cache Manager report access to all clients to reduce attack surface. ↗
- ·Only Squid versions 4.0.23 through 4.7 are affected; versions prior to 4.0.23 and 4.8+ (fixed) are not vulnerable. Red Hat Enterprise Linux 5, 6, and 7 ship unaffected versions of squid/squid34. ↗
- ·On Ubuntu, this issue only affected Ubuntu 19.04 (which shipped Squid 4.x); earlier Ubuntu releases were not affected. ↗
- ·The upstream patch for this CVE is available and can be used to verify patched vs. unpatched deployments. ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8x4r-gffh-rx7f: An issue was discovered in Squid 4
ghsa_unreviewed·2022-05-24
CVE-2019-12527 [HIGH] CWE-787 GHSA-8x4r-gffh-rx7f: An issue was discovered in Squid 4
An issue was discovered in Squid 4.0.23 through 4.7. When checking Basic Authentication with HttpHeader::getAuth, Squid uses a global buffer to store the decoded data. Squid does not check that the decoded length isn't greater than the buffer, leading to a heap-based buffer overflow with user controlled data.
OSV
squid, squid3 vulnerabilities
osv·2019-07-18·CVSS 9.8
CVE-2019-12525 [CRITICAL] squid, squid3 vulnerabilities
squid, squid3 vulnerabilities
It was discovered that Squid incorrectly handled Digest authentication. A
remote attacker could possibly use this issue to cause Squid to crash,
resulting in a denial of service. (CVE-2019-12525)
It was discovered that Squid incorrectly handled Basic authentication. A
remote attacker could use this issue to cause Squid to crash, resulting in
a denial of service, or possibly execute arbitrary code. This issue only
affected Ubuntu 19.04. (CVE-2019-12527)
It was discovered that Squid incorrectly handled Basic authentication. A
remote attacker could possibly use this issue to cause Squid to crash,
resulting in a denial of service. (CVE-2019-12529)
OSV
CVE-2019-12527: An issue was discovered in Squid 4
osv·2019-07-11·CVSS 8.8
CVE-2019-12527 [HIGH] CVE-2019-12527: An issue was discovered in Squid 4
An issue was discovered in Squid 4.0.23 through 4.7. When checking Basic Authentication with HttpHeader::getAuth, Squid uses a global buffer to store the decoded data. Squid does not check that the decoded length isn't greater than the buffer, leading to a heap-based buffer overflow with user controlled data.
Ubuntu
Squid vulnerabilities
vendor_ubuntu·2019-07-18·CVSS 9.8
CVE-2019-12525 [CRITICAL] Squid vulnerabilities
Title: Squid vulnerabilities
Summary: Several security issues were fixed in Squid.
It was discovered that Squid incorrectly handled Digest authentication. A
remote attacker could possibly use this issue to cause Squid to crash,
resulting in a denial of service. (CVE-2019-12525)
It was discovered that Squid incorrectly handled Basic authentication. A
remote attacker could use this issue to cause Squid to crash, resulting in
a denial of service, or possibly execute arbitrary code. This issue only
affected Ubuntu 19.04. (CVE-2019-12527)
It was discovered that Squid incorrectly handled Basic authentication. A
remote attacker could possibly use this issue to cause Squid to crash,
resulting in a denial of service. (CVE-2019-12529)
Instructions: In general, a standard system update will make
Red Hat
squid: heap-based buffer overflow in HttpHeader::getAuth
vendor_redhat·2019-07-12·CVSS 8.8
CVE-2019-12527 [HIGH] CWE-122 squid: heap-based buffer overflow in HttpHeader::getAuth
squid: heap-based buffer overflow in HttpHeader::getAuth
An issue was discovered in Squid 4.0.23 through 4.7. When checking Basic Authentication with HttpHeader::getAuth, Squid uses a global buffer to store the decoded data. Squid does not check that the decoded length isn't greater than the buffer, leading to a heap-based buffer overflow with user controlled data.
A flaw was discovered in Squid versions 4.0.23 through 4.7. When checking Basic Authentication with HttpHeader::getAuth, Squid uses a global buffer to store the decoded data but does not check that the decoded length is not greater than the buffer. This flaw leads to a heap-based buffer overflow with user-controlled data.
Mitigation: Deny ftp:// protocol URLs being proxied and Cache Manager report access to all clients:
acl F
Debian
CVE-2019-12527: squid - An issue was discovered in Squid 4.0.23 through 4.7. When checking Basic Authent...
vendor_debian·2019·CVSS 8.8
CVE-2019-12527 [HIGH] CVE-2019-12527: squid - An issue was discovered in Squid 4.0.23 through 4.7. When checking Basic Authent...
An issue was discovered in Squid 4.0.23 through 4.7. When checking Basic Authentication with HttpHeader::getAuth, Squid uses a global buffer to store the decoded data. Squid does not check that the decoded length isn't greater than the buffer, leading to a heap-based buffer overflow with user controlled data.
Scope: local
bookworm: resolved (fixed in 4.8-1)
bullseye: resolved (fixed in 4.8-1)
forky: resolved (fixed in 4.8-1)
sid: resolved (fixed in 4.8-1)
trixie: resolved (fixed in 4.8-1)
No detection rules found.
No public exploits indexed.
HackerOne
Basic Authentication Heap Overflow
hackerone·2021-08-26·CVSS 8.8
[HIGH] Basic Authentication Heap Overflow
Basic Authentication Heap Overflow
## Summary:
An attacker can get arbitrary data overflowed in the heap via Basic Authorization base64 blob. Even when basic auth isn't configured.
## Report sent to developers
When calling HttpHeader::getAuth the field value will be base64 decoded. The call to the decode method doesn't ensure that the buffer decodedAuthToken is large enough for the decoded string leading to a heap overflow.
```
static char decodedAuthToken[8192];
struct base64_decode_ctx ctx; base64_decode_init(&ctx);
size_t decodedLen = 0;
if (!base64_decode_update(&ctx, &decodedLen, reinterpret_cast(decodedAuthToken), strlen(field), field) || !base64_decode_final(&ctx))
{ return NULL; }
decodedAuthToken[decodedLen] = '\0';
```
```
(gdb) p decodedLen $21 = 43011
```
In my repo steps
Bugzilla
CVE-2019-12527 squid: heap-based buffer overflow in HttpHeader::getAuth [fedora-all]
bugzilla·2019-07-17·CVSS 8.8
CVE-2019-12527 [HIGH] CVE-2019-12527 squid: heap-based buffer overflow in HttpHeader::getAuth [fedora-all]
CVE-2019-12527 squid: heap-based buffer overflow in HttpHeader::getAuth [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported v
Bugzilla
CVE-2019-12527 squid: heap-based buffer overflow in HttpHeader::getAuth
bugzilla·2019-07-17·CVSS 8.8
CVE-2019-12527 [HIGH] CVE-2019-12527 squid: heap-based buffer overflow in HttpHeader::getAuth
CVE-2019-12527 squid: heap-based buffer overflow in HttpHeader::getAuth
An issue was discovered in Squid 4.0.23 through 4.7. When checking Basic
Authentication with HttpHeader::getAuth, Squid uses a global buffer to store the
decoded data. Squid does not check that the decoded length isn't greater than
the buffer, leading to a heap-based buffer overflow with user controlled data.
Reference:
https://github.com/squid-cache/squid/commits/v4
http://www.squid-cache.org/Versions/v4/changesets/
Upstream Patch:
http://www.squid-cache.org/Versions/v4/changesets/squid-4-7f73e9c5d17664b882ed32590e6af310c247f320.patch
Discussion:
Created squid tracking bugs for this issue:
Affects: fedora-all [bug 1730534]
---
External References:
http://www.squid-cache.org/Advisories/SQUID-2019_5.txt
---
M
Checkpoint
26th August – Threat Intelligence Bulletin
blogs_checkpoint·2019-08-26
CVE-2019-12527 26th August – Threat Intelligence Bulletin
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 26th August – Threat Intelligence Bulletin
For the latest discoveries in cyber research for the week of 26th August 2019, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Mastercard has disclosed a data breach that impacted customer data belonging to German and Belgian customers that were part of the company’s Priceless Specials program. The incident was discovered after files of the stolen data, which included credit card numbers as well as personal information, were published online
http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00053.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-11/msg00056.htmlhttp://www.securityfocus.com/bid/109143http://www.squid-cache.org/Versions/v4/changesets/http://www.squid-cache.org/Versions/v4/changesets/squid-4-7f73e9c5d17664b882ed32590e6af310c247f320.patchhttps://access.redhat.com/errata/RHSA-2019:2593https://github.com/squid-cache/squid/commits/v4https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPXN2CLAGN5QSQBTOV5IGVLDOQSRFNTZ/https://seclists.org/bugtraq/2019/Aug/42https://usn.ubuntu.com/4065-1/https://www.debian.org/security/2019/dsa-4507http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00053.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-11/msg00056.htmlhttp://www.securityfocus.com/bid/109143http://www.squid-cache.org/Versions/v4/changesets/http://www.squid-cache.org/Versions/v4/changesets/squid-4-7f73e9c5d17664b882ed32590e6af310c247f320.patchhttps://access.redhat.com/errata/RHSA-2019:2593https://github.com/squid-cache/squid/commits/v4https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPXN2CLAGN5QSQBTOV5IGVLDOQSRFNTZ/https://seclists.org/bugtraq/2019/Aug/42https://usn.ubuntu.com/4065-1/https://www.debian.org/security/2019/dsa-4507
2019-07-11
Published