CVE-2020-8450: Buffer Overflow
An issue was discovered in Squid before 4.10. Due to incorrect buffer management, a remote client can cause a buffer overflow in a Squid instance acting as a reverse proxy.
Other sources
Squid is vulnerable to a buffer overflow, caused by improper bounds checking. By sending a specially-crafted request, a remote attacker could overflow a buffer and execute arbitrary code or cause a denial of service condition on the system.
— IBM
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2020-8450?
CVE-2020-8450 is a vulnerability in Squid before version 4.10 that allows a remote attacker to execute arbitrary code or cause a denial of service.
Which software is affected by CVE-2020-8450?
Squid versions before 4.10 are affected by CVE-2020-8450.
How severe is CVE-2020-8450?
CVE-2020-8450 has a severity rating of 9.8, which is considered critical.
How can I fix CVE-2020-8450?
To fix CVE-2020-8450, you should update Squid to version 4.10 or later.
Where can I find more information about CVE-2020-8450?
You can find more information about CVE-2020-8450 in the following references: [Link 1](http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00012.html), [Link 2](http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00010.html), [Link 3](http://www.squid-cache.org/Advisories/SQUID-2020_1.txt).