RULE(RULE ID:324411)

Rule General Information
Release Date: 2020-03-25
Rule Name: Squid Reverse Proxy Host Header Buffer Overflow Vulnerability (CVE-2020-8450)
Severity:
CVE ID:
Rule Protection Details
Description: An issue was discovered in Squid before 4.10. Due to incorrect buffer management, a remote client can cause a buffer overflow in a Squid instance acting as a reverse proxy.
Impact: A buffer overflow vulnerability can be triggered by an attacker in the context of the vulnerable product. Further attacks includes arbitrary code execution and denial of service.
Affected OS: Windows, Others
Reference: http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00012.html
http://www.squid-cache.org/Advisories/SQUID-2020_1.txt
http://www.squid-cache.org/Versions/v3/3.5/changesets/SQUID-2020_1.patch
http://www.squid-cache.org/Versions/v3/3.5/changesets/squid-3.5-8e657e835965c3a011375feaa0359921c5b3e2dd.patch
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
http://www.squid-cache.org/Advisories/SQUID-2020_1.txt