Description
An issue was discovered in Squid 4.0.23 through 4.7. When checking Basic Authentication with HttpHeader::getAuth, Squid uses a global buffer to store the decoded data. Squid does not check that the decoded length isn't greater than the buffer, leading to a heap-based buffer overflow with user controlled data.
Remediation
References
Related Vulnerabilities
Ruby on Rails CVE-2021-22902 Vulnerability (CVE-2021-22902)
MediaWiki CVE-2023-37305 Vulnerability (CVE-2023-37305)
WordPress Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2024-31210)
WordPress Plugin WP-reCAPTCHA Cross-Site Scripting (3.1.3)
WordPress Plugin PDF & Print Button Joliprint Multiple Cross-Site Scripting Vulnerabilities (1.3.0)