<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Squid Proxy Cache Security Update Advisory SQUID-2020:1]]></title><description><![CDATA[<hr />
<pre><code>Squid Proxy Cache Security Update Advisory SQUID-2020:1
</code></pre>
<hr />
<p dir="auto">Advisory ID:        SQUID-2020:1<br />
Date:               February 03, 2020<br />
Summary:            Improper Input Validation issues<br />
in HTTP Request processing.<br />
Affected versions:  Squid 2.x -&gt; 2.7.STABLE9<br />
Squid 3.x -&gt; 3.5.28<br />
Squid 4.x -&gt; 4.9<br />
Fixed in version:   Squid 4.10</p>
<hr />
<pre><code>http://www.squid-cache.org/Advisories/SQUID-2020_1.txt
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8449
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8450
</code></pre>
<hr />
<p dir="auto">Problem Description:</p>
<p dir="auto">Due to incorrect input validation Squid can interpret crafted<br />
HTTP requests in unexpected ways to access server resources<br />
prohibited by earlier security filters.</p>
<p dir="auto">Due to incorrect buffer management a remote client can cause<br />
a buffer overflow in a Squid acting as reverse-proxy.</p>
<hr />
<p dir="auto">Severity:</p>
<p dir="auto">This issue allows attackers to perform denial of service on the<br />
proxy and all clients using it.</p>
<p dir="auto">This issue potentially allows attackers to bypass security access<br />
controls in systems between client and proxy.</p>
<p dir="auto">This issue potentially allows remote code execution under the<br />
proxy low-privilege level. While restricted, it does have access<br />
to a wide range of information about the network structure and<br />
other clients using the proxy.</p>
<p dir="auto">This issue is limited to Squid acting as a reverse-proxy. Some<br />
effects also require allow_direct permissions.</p>
<hr />
<p dir="auto">Updated Packages:</p>
<p dir="auto">This bug is fixed by Squid version 4.10.</p>
<p dir="auto">is update possible in the short term?</p>
]]></description><link>https://forum.netgate.com/topic/151272/squid-proxy-cache-security-update-advisory-squid-2020-1</link><generator>RSS for Node</generator><lastBuildDate>Thu, 11 Jun 2026 09:23:44 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/151272.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 13 Mar 2020 19:14:27 GMT</pubDate><ttl>60</ttl></channel></rss>