Squid»º³åÇøÒç³öÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-11-07

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-12526 £¬Î£ÏÕ¼¶±ð£º¸ßΣ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-18678 £¬Î£ÏÕ¼¶±ð£ºÖÐΣ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨

CVE±àºÅ£ºCVE-2019-18679 £¬Î£ÏÕ¼¶±ð£ºÖÐΣ £¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


Squid 3.xÖÁ3.5.28(°üÀ¨3.5.28)

ËùÓÐSquid-4.xÖÁ4.8°æ±¾(°üÀ¨4.8)


Îó²î¸ÅÊö


SquidÊÇÒ»Ì×ÊðÀí·þÎñÆ÷ºÍWeb»º´æ·þÎñÆ÷Èí¼þ ¡£¸ÃÈí¼þÌṩ»º´æÍòÎ¬Íø¡¢¹ýÂËÁ÷Á¿¡¢ÊðÀíÉÏÍøµÈ¹¦Ð§ ¡£


Squid¹Ù·½Ðû²¼Çå¾²¸üÐÂÐÞ¸´Á˶à¸öÎó²î £¬ÆäÖÐCVE-2019-12526Ϊ»º³åÇøÒç³ö¸ßΣÎó²î £¬¿ÉÄܵ¼ÖÂÔ¶³Ì´úÂëÖ´ÐÐ £¬¸ÅÊöÈçÏ£º


CVE-2019-12526


ÓÉÓÚ²»×¼È·µÄ»º³åÇøÖÎÀí £¬Ô¶³Ì¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÄ¿µÄ·þÎñÆ÷·¢ËÍÈ«ÐÄÉè¼ÆµÄHTTPÇëÇóÀ´Ê¹ÓôËÎó²î ¡£ÀÖ³ÉʹÓý«µ¼Ö¹¥»÷ÕßÄܹ»Ê¹Ó÷þÎñÆ÷Àú³ÌµÄȨÏÞÖ´ÐÐí§Òâ´úÂë £¬¶ø²»ÀֳɵĹ¥»÷½«µ¼Ö·þÎñÆ÷Àú³ÌÒì³£ÖÕÖ¹ ¡£


CVE-2019-18678


ÔÚÐÂÎÅÆÊÎöʱ £¬ÓÉÓÚ¹ýʧµÄÐÂÎÅÆÊÎö £¬SquidÈÝÒ×·ºÆðHTTPÇëÇó²ð·ÖÎÊÌâ ¡£


CVE-2019-18679


ÓÉÓÚ¹ýʧµÄÊý¾ÝÖÎÀí £¬SquidÔÚ´¦Öóͷ£HTTPÕªÒªÈÏ֤ʱÒý·¢ÐÅϢй¶ ¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP ¡£


ÐÞ¸´½¨Òé


Éý¼¶µ½Squid 4.9£ºhttp://www.squid-cache.org/Versions/v4/ ¡£


¸÷Îó²îÔÝʱ»º½â²½·¥ÈçÏ£º


CVE-2019-12526


¾Ü¾ø urn: ЭÒéµÄ URI ±»ÊðÀí¸øËùÓпͻ§¶Ë£º

acl URN proto URN

http_access deny URN


CVE-2019-18679


1.ÔÚsquid.confÉèÖÃÎļþÖÐÒÆ³ýµô'auth_param digest ...'

2.¹¹½¨Squidʱ¼ÓÉϲÎÊý --disable-auth-basic


²Î¿¼Á´½Ó


http://www.squid-cache.org/Advisories/SQUID-2019_11.txt

http://www.squid-cache.org/Advisories/SQUID-2019_10.txt

http://www.squid-cache.org/Advisories/SQUID-2019_7.txt