An issue was discovered in Squid 3.x and 4.x through 4.8 when the append_domain setting is used (because the appended characters do not properly interact with hostname length restrictions). Due to incorrect message processing, it can inappropriately redirect traffic to origins it should not be delivered to.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2028-1 | squid3 security update |
Debian DLA |
DLA-2278-1 | squid3 security update |
Debian DSA |
DSA-4682-1 | squid security update |
EUVD |
EUVD-2019-8393 | An issue was discovered in Squid 3.x and 4.x through 4.8 when the append_domain setting is used (because the appended characters do not properly interact with hostname length restrictions). Due to incorrect message processing, it can inappropriately redirect traffic to origins it should not be delivered to. |
Ubuntu USN |
USN-4213-1 | Squid vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T01:54:14.540Z
Reserved: 2019-11-04T00:00:00
Link: CVE-2019-18677
No data.
Status : Modified
Published: 2019-11-26T17:15:12.923
Modified: 2024-11-21T04:33:30.820
Link: CVE-2019-18677
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN