CVE-2018-1000027
The Squid Software Foundation Squid HTTP Caching Proxy version prior to version 4.0.23 contains a NULL Pointer Dereference vulnerability in HTTP Response X-Forwarded-For header processing that can result in Denial of Service to all clients of the proxy.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 12.9%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
The Squid Software Foundation Squid HTTP Caching Proxy version prior to version 4.0.23 contains a NULL Pointer Dereference vulnerability in HTTP Response X-Forwarded-For header processing that can result in Denial of Service to all clients of the proxy. This attack appear to be exploitable via Remote HTTP server responding with an X-Forwarded-For header to certain types of HTTP request. This vulnerability appears to have been fixed in 4.0.23 and later.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 12.91% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-476
- Affected
- squid-cache/squid · debian/debian linux · canonical/ubuntu linux
- Source
- cve@mitre.org
References
- http://www.squid-cache.org/Advisories/SQUID-2018_2.txtPatch, Vendor Advisory
- http://www.squid-cache.org/Versions/v3/3.5/changesets/SQUID-2018_2.patchPatch, Vendor Advisory
- http://www.squid-cache.org/Versions/v4/changesets/SQUID-2018_2.patchPatch, Vendor Advisory
- https://github.com/squid-cache/squid/pull/129/filesThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/02/msg00001.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/02/msg00002.htmlMailing List, Third Party Advisory
- https://usn.ubuntu.com/3557-1/Third Party Advisory
- https://usn.ubuntu.com/4059-2/
- https://www.debian.org/security/2018/dsa-4122Third Party Advisory
- http://www.squid-cache.org/Advisories/SQUID-2018_2.txtPatch, Vendor Advisory
- http://www.squid-cache.org/Versions/v3/3.5/changesets/SQUID-2018_2.patchPatch, Vendor Advisory
- http://www.squid-cache.org/Versions/v4/changesets/SQUID-2018_2.patchPatch, Vendor Advisory
- https://github.com/squid-cache/squid/pull/129/filesThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/02/msg00001.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/02/msg00002.htmlMailing List, Third Party Advisory
- https://usn.ubuntu.com/3557-1/Third Party Advisory
- https://usn.ubuntu.com/4059-2/
- https://www.debian.org/security/2018/dsa-4122Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.