Back to Database
Status published
High
CVE-2020-8450
An issue was discovered in Squid before 4.10. Due to...
Vulnerability Description
An issue was discovered in Squid before 4.10. Due to incorrect buffer management, a remote client can cause a buffer overflow in a Squid instance acting as a reverse proxy.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-8450
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.squid-cache.org/Advisories/SQUID-2020_1.txt
- http://www.squid-cache.org/Versions/v4/changesets/squid-4-d8e4715992d0e530871519549add5519cbac0598.patch
- http://www.squid-cache.org/Versions/v3/3.5/changesets/squid-3.5-8e657e835965c3a011375feaa0359921c5b3e2dd.patch
- http://www.squid-cache.org/Versions/v4/changesets/squid-4-b3a0719affab099c684f1cd62b79ab02816fa962.patch
- http://www.squid-cache.org/Versions/v4/changesets/SQUID-2020_1.patch
- http://www.squid-cache.org/Versions/v3/3.5/changesets/SQUID-2020_1.patch
- https://usn.ubuntu.com/4289-1/
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00012.html
- https://security.gentoo.org/glsa/202003-34
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/G6W2IQ7QV2OGREFFUBNVZIDD3RJBDE4R/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TSU6SPANL27AGK5PCGBJOKG4LUWA555J/
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00010.html
- https://www.debian.org/security/2020/dsa-4682
- https://lists.debian.org/debian-lts-announce/2020/07/msg00009.html
- https://security.netapp.com/advisory/ntap-20210304-0002/
More from squid-cache
View All →CVE-2025-62168
Squid vulnerable to information disclosure via authentication credential leakage in error handling
Critical
10
CVE-2025-54574
Squid's URN Handling can lead to Buffer Overflow
Critical
9.3
CVE-2024-45802
Squid Denial of Service
High
7.5
CVE-2024-37894
Squid vulnerable to heap corruption in ESI assign
Medium
6.3
CVE-2024-25617
Denial of Service in HTTP Header parser in squid proxy
Medium
5.3
Affected Vendor
squid-cache
View all reports →Affected Software
squid, ubuntu linux, leap, fedora, debian linux
Vulnerable Versions:
0, 16.04, 18.04, 19.10, 15.1, 30, 31, 9.0, 10.0
Timeline
Official Publish:
February 4th, 2020
Last Modified:
August 4th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.