Vulnerability Name: | CVE-2020-14058 (CCN-184300) | ||||||||||||||||||
Assigned: | 2020-06-19 | ||||||||||||||||||
Published: | 2020-06-19 | ||||||||||||||||||
Updated: | 2022-04-28 | ||||||||||||||||||
Summary: | An issue was discovered in Squid before 4.12 and 5.x before 5.0.3. Due to use of a potentially dangerous function, Squid and the default certificate validation helper are vulnerable to a Denial of Service when opening a TLS connection to an attacker-controlled server for HTTPS. This occurs because unrecognized error values are mapped to NULL, but later code expects that each error value is mapped to a valid error string. | ||||||||||||||||||
CVSS v3 Severity: | 7.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) 6.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
7.5 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H/E:U/RL:O/RC:C)
6.7 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
| ||||||||||||||||||
Vulnerability Type: | CWE-noinfo CWE-676 | ||||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2020-14058 Source: CONFIRM Type: Vendor Advisory http://www.squid-cache.org/Advisories/SQUID-2020_6.txt Source: MISC Type: Patch, Vendor Advisory http://www.squid-cache.org/Versions/v4/changesets/squid-4-93f5fda134a2a010b84ffedbe833d670e63ba4be.patch Source: MISC Type: Patch, Vendor Advisory http://www.squid-cache.org/Versions/v5/changesets/squid-5-c6d1a4f6a2cbebceebc8a3fcd8f539ceb7b7f723.patch Source: XF Type: UNKNOWN squid-cve202014058-dos(184300) Source: CCN Type: Squid Proxy Cache Security Update Advisory SQUID-2020:6 Denial of Service issue in TLS handshake Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2020-cbebc5617e Source: CONFIRM Type: Third Party Advisory https://security.netapp.com/advisory/ntap-20210312-0001/ Source: CCN Type: WhiteSource Vulnerability Database CVE-2020-14058 | ||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration RedHat 1: Configuration RedHat 2: Configuration CCN 1: ![]() | ||||||||||||||||||
Oval Definitions | |||||||||||||||||||
| |||||||||||||||||||
BACK |