Vulnerability Description
An issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resources that are otherwise forbidden. This occurs because the attacker can overflow the nonce reference counter (a short integer). Remote code execution may occur if the pooled token credentials are freed (instead of replayed as valid credentials).
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Squid-Cache | Squid | >= 3.0, <= 3.5.28 |
| Debian | Debian Linux | 9.0 |
| Opensuse | Leap | 15.1 |
| Fedoraproject | Fedora | 30 |
| Canonical | Ubuntu Linux | 16.04 |
Related Weaknesses (CWE)
References
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00018.htmlMailing ListThird Party Advisory
- http://master.squid-cache.org/Versions/v4/changesets/squid-4-eeebf0f37a72a2de083Vendor Advisory
- http://www.openwall.com/lists/oss-security/2020/04/23/2Mailing ListThird Party Advisory
- http://www.squid-cache.org/Versions/v4/changesets/squid-4-eeebf0f37a72a2de08348ePatchVendor Advisory
- https://bugzilla.suse.com/show_bug.cgi?id=1170313Issue TrackingThird Party Advisory
- https://github.com/squid-cache/squid/commit/eeebf0f37a72a2de08348e85ae34b02c34e9PatchThird Party Advisory
- https://github.com/squid-cache/squid/pull/585PatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/07/msg00009.htmlMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://security.gentoo.org/glsa/202005-05Third Party Advisory
- https://security.netapp.com/advisory/ntap-20210304-0004/Third Party Advisory
- https://usn.ubuntu.com/4356-1/Third Party Advisory
- https://www.debian.org/security/2020/dsa-4682Third Party Advisory
FAQ
What is CVE-2020-11945?
CVE-2020-11945 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An issue was discovered in Squid before 5.0.2. A remote attacker can replay a sniffed Digest Authentication nonce to gain access to resources that are otherwise forbidden. This occurs because the atta...
How severe is CVE-2020-11945?
CVE-2020-11945 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-11945?
Check the references section above for vendor advisories and patch information. Affected products include: Squid-Cache Squid, Debian Debian Linux, Opensuse Leap, Fedoraproject Fedora, Canonical Ubuntu Linux.