CERT-In Vulnerability Note
CIVN-2021-0258
Security Restriction Bypass Vulnerability in Squid Products
Original Issue Date:October 12, 2021
Severity Rating: HIGH
Software Affected
- Squid versions 5.0.6 to 5.1
Overview
A vulnerability has been reported in Squid, a caching and forwarding HTTP web proxy, which could be exploited by an attacker to bypass security restriction on the targeted system.
Description
This vulnerability exists in Squid due to improper certificate validation when the TLS server certificate is signed by multiple CAs or this may also occur in cases of broken server certificate chains. An attacker could exploit this vulnerability by allowing a remote server to obtain security trust when the trust is not valid. This indication of trust may be passed along to clients thereby giving access to unsafe or hijacked services.
Successful exploitation of this vulnerability could allow an attacker to bypass security restrictions and conduct other attacks on the targeted system.
Solution
Patch to latest version Squid 5:
http://www.squid-cache.org/Versions/v5/changesets/squid-5-33b4359f16cf9ed15a6d709a57a4b06e4222cfe.patch
Vendor Information
http://www.squid-cache.org/
References
Squid
https://github.com/squid-cache/squid/security/advisories/GHSA-47m4-g3mv-9q5r
CVE Name
CVE-2021-41611
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|