cbcvebase.
CVE-2019-12527
published 2019-07-11

CVE-2019-12527: An issue was discovered in Squid 4.0.23 through 4.7. When checking Basic Authentication with HttpHeader::getAuth, Squid uses a global buffer to store the…

PriorityP265high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
49.04%
98.8th percentile
An issue was discovered in Squid 4.0.23 through 4.7. When checking Basic Authentication with HttpHeader::getAuth, Squid uses a global buffer to store the decoded data. Squid does not check that the decoded length isn't greater than the buffer, leading to a heap-based buffer overflow with user controlled data.

Affected

22 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiansquid< squid 4.8-1 (bookworm)squid 4.8-1 (bookworm)
fedoraprojectfedora
redhatenterprise_linux
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_eus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_tus
redhatenterprise_linux_server_tus
redhatenterprise_linux_server_tus
squid-cachesquid4.0.23 – 4.7
squidsquid>= 0 < 4.8-14.8-1
squidsquid>= 0 < 4.8-14.8-1
squidsquid>= 0 < 4.8-14.8-1
squidsquid>= 0 < 4.8-14.8-1

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability is triggered via Basic Authentication headers — monitor for oversized or malformed Base64-encoded Authorization: Basic headers sent to Squid proxy (versions 4.0.23 through 4.7), which cause a heap-based buffer overflow in HttpHeader::getAuth.
  • Apply ACL-based mitigation by denying FTP protocol URLs being proxied and Cache Manager report access to all clients to reduce attack surface.
  • ·Only Squid versions 4.0.23 through 4.7 are affected; versions prior to 4.0.23 and 4.8+ (fixed) are not vulnerable. Red Hat Enterprise Linux 5, 6, and 7 ship unaffected versions of squid/squid34.
  • ·On Ubuntu, this issue only affected Ubuntu 19.04 (which shipped Squid 4.x); earlier Ubuntu releases were not affected.
  • ·The upstream patch for this CVE is available and can be used to verify patched vs. unpatched deployments.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.