SB2018022817 - NULL pointer derefenrece in squid (Alpine package)
Published: February 28, 2018
Security Bulletin ID
SB2018022817
Severity
Medium
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Remote access
Highest impact
Denial of service
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) NULL pointer derefenrece (CVE-ID: CVE-2018-1000024)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.The vulnerability exists due to incorrect pointer handling when processing ESI responses. A remote attacker can supply a specially crafted response to the vulnerable server and trigger application crash.
Remediation
Install update from vendor's website.
References
- https://git.alpinelinux.org/aports/commit/?id=a2e4a10786598b2f40879a608a3090b4f1242065
- https://git.alpinelinux.org/aports/commit/?id=e669c04c87f3b6f9826273154aebe26e89d75dc8
- https://git.alpinelinux.org/aports/commit/?id=1bd365a6732f045db6dd96f516dec5764f0c8c57
- https://git.alpinelinux.org/aports/commit/?id=48e59c02864ce11fac3e2ff3529f2e1f5d1b7f1e
- https://git.alpinelinux.org/aports/commit/?id=a93510d1c69bc8f6e6fd0e2781ffcad140585f08
- https://git.alpinelinux.org/aports/commit/?id=034cdecfa97d19069fbd8c757be0bca3b7096645
- https://git.alpinelinux.org/aports/commit/?id=e1bccabacec574093facca45f725b55426c91d2f
- https://git.alpinelinux.org/aports/commit/?id=fe411eab506c68e71ec5d809b2d3ad31f79960b4
- https://git.alpinelinux.org/aports/commit/?id=70734a7d94989236c215eda0309e71320585fcdc