ZeroHour

CVE-2019-18677

CVSS 3.1
6.1 medium
EPSS
7%p94
Published
()
Modified
Description

An issue was discovered in Squid 3.x and 4.x through 4.8 when the append_domain setting is used (because the appended characters do not properly interact with hostname length restrictions). Due to incorrect message processing, it can inappropriately redirect traffic to origins it should not be delivered to.

Vendors
squid-cachecanonicalfedoraproject
Products
squid, ubuntu linux, fedora
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.