Lucene search

K
freebsdFreeBSD57C1C2EE-7914-11EA-90BF-0800276545C1
HistoryFeb 10, 2020 - 12:00 a.m.

Squid -- multiple vulnerabilities

2020-02-1000:00:00
vuxml.freebsd.org
19

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.919 High

EPSS

Percentile

98.9%

The Squid developers reports:

Improper Input Validation issues in HTTP Request
processing (CVE-2020-8449, CVE-2020-8450).
Information Disclosure issue in FTP Gateway
(CVE-2019-12528).
Buffer Overflow issue in ext_lm_group_acl helper
(CVE-2020-8517).

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchsquid< 4.10UNKNOWN

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.919 High

EPSS

Percentile

98.9%