Bug 1113668 - (CVE-2018-19131) VUL-0: CVE-2018-19131: squid: Cross-Site Scripting vulnerability in the TLS error handling
(CVE-2018-19131)
VUL-0: CVE-2018-19131: squid: Cross-Site Scripting vulnerability in the TLS e...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Major
: ---
Assigned To: Security Team bot
Security Team bot
https://smash.suse.de/issue/218199/
CVSSv3:SUSE:CVE-2018-19131:7.2:(AV:N...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2018-10-29 08:08 UTC by Karol Babioch
Modified: 2022-10-13 13:49 UTC (History)
3 users (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Karol Babioch 2018-10-29 08:08:41 UTC
* An Cross-Site Scripting vulnerability (CWE-74, CWE-79) has been found
in the TLS error handling by Squid.

Several fields of X.509 certificates can contain HTML syntax and were
not being correctly quoted/encoded before inserting into HTML error
pages generated by the proxy. This issue allows an attacker to craft a
X.509 certificate that both triggers an error and alters how that error
is displayed by a client such as a Browser.

Affected Versions:
 Squid 3.1.12.1 -> 3.1.23
 Squid 4.0 -> 4.3

Squid 3.1.12 and older including Squid-2.x are not vulnerable.


The patch for Squid-3.5 should apply relatively cleanly to all v3.x
affected versions.

<http://www.squid-cache.org/Versions/v3/3.5/changesets/squid-3.5-f1657a9decc820f748fa3aff68168d3145258031.patch>

<http://www.squid-cache.org/Versions/v4/changesets/squid-4-828245b90206602014ce057c3db39fb80fcc4b08.patch>

<http://www.squid-cache.org/Versions/v5/changesets/squid-5-6feeb15ff312f3e145763adf8d234ed6a0b3f11d.patch>

<http://www.squid-cache.org/Advisories/SQUID-2018_4.txt>
Comment 1 Karol Babioch 2018-10-29 08:09:48 UTC
This does not have CVEs yet, although they were requested according to the oss-sec thread.

Also, this has been added:

> Apologies, these versions are also affected:
>
>  Squid 3.2.0.4 -> 3.5.28
Comment 2 Adam Majer 2018-10-29 12:48:22 UTC
Fixes ready, pending CVE numbers.
Comment 4 Karol Babioch 2018-11-09 09:32:16 UTC
Requested CVE Mitre, let's see if they are willing to assign one for this, since nothing is happening on the DWF front.
Comment 5 Karol Babioch 2018-11-09 10:17:25 UTC
Mitre was really fast here: CVE-2018-19131
Comment 8 Adam Majer 2018-11-09 16:11:55 UTC
Fixes submitted to all affected codestreams. Reassigning to security team
Comment 9 Swamp Workflow Management 2018-11-15 17:10:28 UTC
SUSE-SU-2018:3771-1: An update that solves two vulnerabilities and has three fixes is now available.

Category: security (important)
Bug References: 1082318,1112066,1112695,1113668,1113669
CVE References: CVE-2018-19131,CVE-2018-19132
Sources used:
SUSE Linux Enterprise Server 12-SP3 (src):    squid-3.5.21-26.12.1
Comment 10 Swamp Workflow Management 2018-11-16 20:18:25 UTC
SUSE-SU-2018:3786-1: An update that solves two vulnerabilities and has three fixes is now available.

Category: security (important)
Bug References: 1082318,1112066,1112695,1113668,1113669
CVE References: CVE-2018-19131,CVE-2018-19132
Sources used:
SUSE Linux Enterprise Module for Server Applications 15 (src):    squid-4.4-5.3.2
Comment 11 Swamp Workflow Management 2018-11-16 20:21:12 UTC
SUSE-SU-2018:3790-1: An update that fixes one vulnerability is now available.

Category: security (important)
Bug References: 1113668
CVE References: CVE-2018-19131
Sources used:
SUSE Linux Enterprise Server 11-SP4 (src):    squid3-3.1.23-8.16.37.9.1
SUSE Linux Enterprise Debuginfo 11-SP4 (src):    squid3-3.1.23-8.16.37.9.1
Comment 12 Swamp Workflow Management 2018-11-20 20:21:44 UTC
openSUSE-SU-2018:3818-1: An update that solves two vulnerabilities and has three fixes is now available.

Category: security (important)
Bug References: 1082318,1112066,1112695,1113668,1113669
CVE References: CVE-2018-19131,CVE-2018-19132
Sources used:
openSUSE Leap 15.0 (src):    squid-4.4-lp150.4.3.2
Comment 13 Swamp Workflow Management 2018-11-20 20:26:18 UTC
openSUSE-SU-2018:3825-1: An update that solves two vulnerabilities and has three fixes is now available.

Category: security (important)
Bug References: 1082318,1112066,1112695,1113668,1113669
CVE References: CVE-2018-19131,CVE-2018-19132
Sources used:
openSUSE Leap 42.3 (src):    squid-3.5.21-18.1
Comment 14 Swamp Workflow Management 2018-12-07 11:15:23 UTC
SUSE-SU-2018:3771-2: An update that solves two vulnerabilities and has three fixes is now available.

Category: security (important)
Bug References: 1082318,1112066,1112695,1113668,1113669
CVE References: CVE-2018-19131,CVE-2018-19132
Sources used:
SUSE Linux Enterprise Server 12-SP4 (src):    squid-3.5.21-26.12.1
Comment 15 Swamp Workflow Management 2019-05-08 11:30:25 UTC
This is an autogenerated message for OBS integration:
This bug (1113668) was mentioned in
https://build.opensuse.org/request/show/701549 Factory / squid
Comment 17 Wolfgang Frisch 2020-10-19 16:08:06 UTC
SLE12 has reached its end-of-life.
Resolved.