CVE-2020-11945
A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resources that are otherwise forbidden.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 27.2%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
An issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resources that are otherwise forbidden. This occurs because the attacker can overflow the nonce reference counter (a short integer). Remote code execution may occur if the pooled token credentials are freed (instead of replayed as valid credentials).
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 27.25% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-190
- Affected
- squid-cache/squid · debian/debian linux · opensuse/leap · fedoraproject/fedora · canonical/ubuntu linux
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00018.htmlMailing List, Third Party Advisory
- http://master.squid-cache.org/Versions/v4/changesets/squid-4-eeebf0f37a72a2de08348e85ae34b02c34e9a811.patchVendor Advisory
- http://www.openwall.com/lists/oss-security/2020/04/23/2Mailing List, Third Party Advisory
- http://www.squid-cache.org/Versions/v4/changesets/squid-4-eeebf0f37a72a2de08348e85ae34b02c34e9a811.patchPatch, Vendor Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=1170313Issue Tracking, Third Party Advisory
- https://github.com/squid-cache/squid/commit/eeebf0f37a72a2de08348e85ae34b02c34e9a811Patch, Third Party Advisory
- https://github.com/squid-cache/squid/pull/585Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/07/msg00009.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4FWQRYZJPHAZBLXJ56FPCHJN5X2FP3VA/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H4MWXEZAJSOGRJSS2JCJK4WBSND4IV46/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RV2VZWFJNO3B56IVN56HHKJASG5DYUIX/
- https://security.gentoo.org/glsa/202005-05Third Party Advisory
- https://security.netapp.com/advisory/ntap-20210304-0004/Third Party Advisory
- https://usn.ubuntu.com/4356-1/Third Party Advisory
- https://www.debian.org/security/2020/dsa-4682Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00018.htmlMailing List, Third Party Advisory
- http://master.squid-cache.org/Versions/v4/changesets/squid-4-eeebf0f37a72a2de08348e85ae34b02c34e9a811.patchVendor Advisory
- http://www.openwall.com/lists/oss-security/2020/04/23/2Mailing List, Third Party Advisory
- http://www.squid-cache.org/Versions/v4/changesets/squid-4-eeebf0f37a72a2de08348e85ae34b02c34e9a811.patchPatch, Vendor Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=1170313Issue Tracking, Third Party Advisory
- https://github.com/squid-cache/squid/commit/eeebf0f37a72a2de08348e85ae34b02c34e9a811Patch, Third Party Advisory
- https://github.com/squid-cache/squid/pull/585Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/07/msg00009.htmlMailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4FWQRYZJPHAZBLXJ56FPCHJN5X2FP3VA/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H4MWXEZAJSOGRJSS2JCJK4WBSND4IV46/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RV2VZWFJNO3B56IVN56HHKJASG5DYUIX/
- https://security.gentoo.org/glsa/202005-05Third Party Advisory
- https://security.netapp.com/advisory/ntap-20210304-0004/Third Party Advisory
- https://usn.ubuntu.com/4356-1/Third Party Advisory
- https://www.debian.org/security/2020/dsa-4682Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.