Severity
5.9MEDIUMNVD
EPSS
16.2%
top 5.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 11
Latest updateMay 24

Description

An issue was discovered in Squid 2.x through 2.7.STABLE9, 3.x through 3.5.28, and 4.x through 4.7. When Squid is configured to use Basic Authentication, the Proxy-Authorization header is parsed via uudecode. uudecode determines how many bytes will be decoded by iterating over the input and checking its table. The length is then used to start decoding the string. There are no checks to ensure that the length it calculates isn't greater than the input buffer. This leads to adjacent memory being de

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages3 packages

NVDsquid-cache/squid2.02.7+3
Debiansquid/squid< 4.8-1+3
NVDopensuse/leap15.0, 15.1+1

Also affects: Debian Linux 10.0, 8.0, 9.0, Fedora 29, Ubuntu Linux 12.04, 16.04, 18.04, 19.04

Patches

🔴Vulnerability Details

4
GHSA
GHSA-99gm-2796-7c8p: An issue was discovered in Squid 22022-05-24
OSV
squid, squid3 vulnerabilities2019-07-18
CVEList
CVE-2019-12529: An issue was discovered in Squid 22019-07-11
OSV
CVE-2019-12529: An issue was discovered in Squid 22019-07-11

📋Vendor Advisories

4
Ubuntu
Squid vulnerabilities2019-07-22
Ubuntu
Squid vulnerabilities2019-07-18
Red Hat
squid: Out of bounds read in Proxy-Authorization header causes DoS2019-07-11
Debian
CVE-2019-12529: squid - An issue was discovered in Squid 2.x through 2.7.STABLE9, 3.x through 3.5.28, an...2019

💬Community

2
Bugzilla
CVE-2019-12529 squid: Out of bounds read in Proxy-Authorization header causes DoS2019-07-17
Bugzilla
CVE-2019-12529 squid: information disclosure in Proxy-Authorization header [fedora-all]2019-07-17
CVE-2019-12529 — Out-of-bounds Read in Squid | cvebase