First published: Tue Jun 30 2020(Updated: )
An issue was discovered in http/ContentLengthInterpreter.cc in Squid before 4.12 and 5.x before 5.0.3. A Request Smuggling and Poisoning attack can succeed against the HTTP cache. The client sends an HTTP request with a Content-Length header containing "+\ "-" or an uncommon shell whitespace character prefix to the length field-value.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Squid-Cache Squid | >=2.0<=2.6 | |
Squid-Cache Squid | >=3.1<=3.5.28 | |
Squid-Cache Squid | >=4.0<4.12 | |
Squid-Cache Squid | >=5.0<5.0.3 | |
Squid-Cache Squid | =2.7 | |
Squid-Cache Squid | =2.7-stable2 | |
Squid-Cache Squid | =2.7-stable3 | |
Squid-Cache Squid | =2.7-stable4 | |
Squid-Cache Squid | =2.7-stable5 | |
Squid-Cache Squid | =2.7-stable6 | |
Squid-Cache Squid | =2.7-stable7 | |
Squid-Cache Squid | =2.7-stable8 | |
Squid-Cache Squid | =2.7-stable9 | |
Fedoraproject Fedora | =31 | |
IBM Security Guardium | <=10.5 | |
IBM Security Guardium | <=10.6 | |
IBM Security Guardium | <=11.0 | |
IBM Security Guardium | <=11.1 | |
IBM Security Guardium | <=11.2 | |
IBM Security Guardium | <=11.3 | |
debian/squid | 4.13-10+deb11u3 5.7-2+deb12u2 6.10-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-15049 is a vulnerability in Squid-Cache Squid that allows for HTTP request smuggling due to improper input validation.
CVE-2020-15049 has a severity rating of critical, with a CVSS score of 9.9.
CVE-2020-15049 affects Squid versions before 4.12 and 5.x before 5.0.3.
To fix CVE-2020-15049 in Squid, update to version 4.12 or 5.0.3 or later.
More information about CVE-2020-15049 can be found at the following references: - [http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00012.html](http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00012.html) - [http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00017.html](http://lists.opensuse.org/opensuse-security-announce/2020-09/msg00017.html) - [http://www.squid-cache.org/Versions/v4/changesets/squid-4-ea12a34d338b962707d5078d6d1fc7c6eb119a22.patch](http://www.squid-cache.org/Versions/v4/changesets/squid-4-ea12a34d338b962707d5078d6d1fc7c6eb119a22.patch)