CVE-2019-18677

NameCVE-2019-18677
DescriptionAn issue was discovered in Squid 3.x and 4.x through 4.8 when the append_domain setting is used (because the appended characters do not properly interact with hostname length restrictions). Due to incorrect message processing, it can inappropriately redirect traffic to origins it should not be delivered to.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-2028-1, DLA-2278-1, DSA-4682-1, ELA-271-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
squid (PTS)buster4.6-1+deb10u7fixed
buster (security)4.6-1+deb10u8fixed
bullseye (security), bullseye4.13-10+deb11u2fixed
sid, bookworm5.7-1fixed
squid3 (PTS)jessie, jessie (lts)3.5.23-5+deb8u6fixed
stretch (security)3.5.23-5+deb9u7fixed
stretch (lts), stretch3.5.23-5+deb9u9fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
squidsourcewheezy(unfixed)end-of-life
squidsourcebuster4.6-1+deb10u2DSA-4682-1
squidsource(unstable)4.9-1
squid3sourcewheezy(unfixed)end-of-life
squid3sourcejessie3.5.23-5+deb8u1ELA-271-1
squid3sourcestretch3.5.23-5+deb9u2DLA-2278-1
squid3source(unstable)(unfixed)

Notes

Squid 4: http://www.squid-cache.org/Versions/v4/changesets/squid-4-36492033ea4097821a4f7ff3ddcb971fbd1e8ba0.patch
Squid 3.5: http://www.squid-cache.org/Versions/v3/3.5/changesets/squid-3.5-e5f1813a674848dde570f7920873e1071f96e0b4.patch
http://www.squid-cache.org/Advisories/SQUID-2019_9.txt

Search for package or bug name: Reporting problems