{"id":"SUSE-SU-2020:14460-1","summary":"Security update for squid3","details":"This update for squid3 fixes the following issues:\n\n- Fixed a Cache Poisoning and Request Smuggling\n  attack (CVE-2020-15049, bsc#1173455)\n- Fixed incorrect buffer handling that can\n  result in cache poisoning, remote execution, and\n  denial of service attacks when processing ESI responses\n  (CVE-2019-12519, CVE-2019-12521, bsc#1169659)\n\n- Fixed handling of hostname in\n  cachemgr.cgi (CVE-2019-18860, bsc#1167373)\n- Fixed a potential remote execution vulnerability\n  when using HTTP Digest Authentication (CVE-2020-11945, bsc#1170313)\n- Fixed a potential ACL bypass, cache-bypass\n  and cross-site scripting attack when processing invalid HTTP\n  Request messages (CVE-2019-12520, CVE-2019-12524, bsc#1170423)\n- Fixed a potential denial of service when\n  processing TLS certificates during HTTPS connections\n  (CVE-2020-14059, bsc#1173304)\n\n- Fixed a potential denial of service associated\n  with incorrect buffer management of HTTP Basic Authentication\n  credentials (bsc#1141329, CVE-2019-12529)\n- Fixed an incorrect buffer management resulting\n  in vulnerability to a denial of service during processing of\n  HTTP Digest Authentication credentials (bsc#1141332, CVE-2019-12525)\n- Fix XSS via user_name or auth parameter\n  in cachemgr.cgi (bsc#1140738, CVE-2019-13345)\n- Fixed a potential code execution vulnerability\n  (CVE-2019-12526, bsc#1156326)\n- Fixed HTTP Request Splitting in HTTP\n  message processing and information disclosure in\n  HTTP Digest Authentication\n  (CVE-2019-18678, CVE-2019-18679, bsc#1156323, bsc#1156324)\n- Fixed a security issue allowing a remote\n  client ability to cause use a buffer overflow when squid is\n  acting as reverse-proxy.\n  (CVE-2020-8449, CVE-2020-8450, bsc#1162687)\n- Fixed a security issue allowing for information\n  disclosure in FTP gateway (CVE-2019-12528, bsc#1162689)\n- Fixed a security issue in ext_lm_group_acl\n  when processing NTLM Authentication credentials.\n  (CVE-2020-8517, bsc#1162691)\n\n- Fixed Cross-Site Request Forgery in\n  HTTP Request processing (CVE-2019-18677, bsc#1156328)\n\n- Disable urn parsing and parsing of\n  unknown schemes (bsc#1156329, CVE-2019-12523, CVE-2019-18676)\n","modified":"2026-03-11T07:14:14.850039Z","published":"2020-08-24T12:06:51Z","related":["CVE-2019-12519","CVE-2019-12520","CVE-2019-12521","CVE-2019-12523","CVE-2019-12524","CVE-2019-12525","CVE-2019-12526","CVE-2019-12528","CVE-2019-12529","CVE-2019-13345","CVE-2019-18676","CVE-2019-18677","CVE-2019-18678","CVE-2019-18679","CVE-2019-18860","CVE-2020-11945","CVE-2020-14059","CVE-2020-15049","CVE-2020-8449","CVE-2020-8450","CVE-2020-8517"],"upstream":["CVE-2019-12519","CVE-2019-12520","CVE-2019-12521","CVE-2019-12523","CVE-2019-12524","CVE-2019-12525","CVE-2019-12526","CVE-2019-12528","CVE-2019-12529","CVE-2019-13345","CVE-2019-18676","CVE-2019-18677","CVE-2019-18678","CVE-2019-18679","CVE-2019-18860","CVE-2020-11945","CVE-2020-14059","CVE-2020-15049","CVE-2020-8449","CVE-2020-8450","CVE-2020-8517"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2020/suse-su-202014460-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1140738"},{"type":"REPORT","url":"https://bugzilla.suse.com/1141329"},{"type":"REPORT","url":"https://bugzilla.suse.com/1141332"},{"type":"REPORT","url":"https://bugzilla.suse.com/1156323"},{"type":"REPORT","url":"https://bugzilla.suse.com/1156324"},{"type":"REPORT","url":"https://bugzilla.suse.com/1156326"},{"type":"REPORT","url":"https://bugzilla.suse.com/1156328"},{"type":"REPORT","url":"https://bugzilla.suse.com/1156329"},{"type":"REPORT","url":"https://bugzilla.suse.com/1162687"},{"type":"REPORT","url":"https://bugzilla.suse.com/1162689"},{"type":"REPORT","url":"https://bugzilla.suse.com/1162691"},{"type":"REPORT","url":"https://bugzilla.suse.com/1167373"},{"type":"REPORT","url":"https://bugzilla.suse.com/1169659"},{"type":"REPORT","url":"https://bugzilla.suse.com/1170313"},{"type":"REPORT","url":"https://bugzilla.suse.com/1170423"},{"type":"REPORT","url":"https://bugzilla.suse.com/1173304"},{"type":"REPORT","url":"https://bugzilla.suse.com/1173455"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-12519"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-12520"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-12521"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-12523"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-12524"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-12525"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-12526"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-12528"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-12529"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-13345"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-18676"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-18677"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-18678"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-18679"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-18860"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-11945"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-14059"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15049"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-8449"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-8450"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-8517"}],"affected":[{"package":{"name":"squid3","ecosystem":"SUSE:Linux Enterprise Point of Sale 11 SP3","purl":"pkg:rpm/suse/squid3&distro=SUSE%20Linux%20Enterprise%20Point%20of%20Sale%2011%20SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.23-8.16.37.12.1"}]}],"ecosystem_specific":{"binaries":[{"squid3":"3.1.23-8.16.37.12.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2020:14460-1.json"}},{"package":{"name":"squid3","ecosystem":"SUSE:Linux Enterprise Server 11 SP4-LTSS","purl":"pkg:rpm/suse/squid3&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.23-8.16.37.12.1"}]}],"ecosystem_specific":{"binaries":[{"squid3":"3.1.23-8.16.37.12.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2020:14460-1.json"}}],"schema_version":"1.7.5"}