Severity
7.3HIGHNVD
EPSS
46.3%
top 2.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 4
Latest updateMay 24

Description

An issue was discovered in Squid before 4.10. Due to incorrect buffer management, a remote client can cause a buffer overflow in a Squid instance acting as a reverse proxy.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:LExploitability: 3.9 | Impact: 3.4

Affected Packages3 packages

NVDsquid-cache/squid< 4.10
Debiansquid/squid< 4.10-1+3
NVDopensuse/leap15.1

Also affects: Debian Linux 10.0, 9.0, Fedora 30, 31, Ubuntu Linux 16.04, 18.04, 19.10

Patches

🔴Vulnerability Details

4
GHSA
GHSA-vrcq-r42v-wc44: An issue was discovered in Squid before 42022-05-24
OSV
squid, squid3 vulnerabilities2020-02-20
CVEList
CVE-2020-8450: An issue was discovered in Squid before 42020-02-04
OSV
CVE-2020-8450: An issue was discovered in Squid before 42020-02-04

📋Vendor Advisories

3
Ubuntu
Squid vulnerabilities2020-02-20
Red Hat
squid: Buffer overflow in reverse-proxy configurations2020-02-03
Debian
CVE-2020-8450: squid - An issue was discovered in Squid before 4.10. Due to incorrect buffer management...2020

💬Community

2
Bugzilla
CVE-2020-8450 squid: Buffer overflow in a Squid acting as reverse-proxy [fedora-all]2020-02-05
Bugzilla
CVE-2020-8450 squid: Buffer overflow in reverse-proxy configurations2020-02-05
CVE-2020-8450 — Incorrect Calculation of Buffer Size | cvebase