HTTP: Squid Proxy Authorization Denail Of Service

This signature detects attempts to exploit a known vulnerability against Squid Proxy. A successful attack can lead to Denial of service.

Extended Description

An issue was discovered in Squid 3.3.9 through 3.5.28 and 4.x through 4.7. When Squid is configured to use Digest authentication, it parses the header Proxy-Authorization. It searches for certain tokens such as domain, uri, and qop. Squid checks if this token's value starts with a quote and ends with one. If so, it performs a memcpy of its length minus 2. Squid never checks whether the value is just a single quote (which would satisfy its requirements), leading to a memcpy of its length minus 1.

Affected Products

Debian debian_linux

References

CVE: CVE-2019-12525

Short Name
HTTP:HEADER:SQUID-PROXY-AUTH
Severity
Major
Recommended
False
Recommended Action
None
Category
HTTP
Keywords
Authorization CVE-2019-12525 Denail Of Proxy Service Squid
Release Date
01/05/2020
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3590
False Positive
Unknown
Vendors

Opensuse

Fedoraproject

Squid-cache

Debian

Canonical

CVSS Score

7.5

Found a potential security threat?