Bug 1140738 - (CVE-2019-13345) VUL-0: CVE-2019-13345: squid,squid3: XSS via user_name or auth parameter in cachemgr.cgi
(CVE-2019-13345)
VUL-0: CVE-2019-13345: squid,squid3: XSS via user_name or auth parameter in c...
Status: RESOLVED FIXED
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Normal
: ---
Assigned To: Adam Majer
Security Team bot
https://smash.suse.de/issue/236576/
maint:released:sle10-sp3:64328 CVSSv3...
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2019-07-08 14:48 UTC by Marcus Meissner
Modified: 2021-01-17 08:09 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Comment 2 Swamp Workflow Management 2019-07-16 09:00:08 UTC
This is an autogenerated message for OBS integration:
This bug (1140738) was mentioned in
https://build.opensuse.org/request/show/715608 Factory / squid
Comment 6 Swamp Workflow Management 2019-07-16 16:30:07 UTC
This is an autogenerated message for OBS integration:
This bug (1140738) was mentioned in
https://build.opensuse.org/request/show/715745 Factory / squid
Comment 8 Swamp Workflow Management 2019-07-18 13:01:21 UTC
An update workflow for this issue was started.
This issue was rated as moderate.
Please submit fixed packages until 2019-08-01.
When done, reassign the bug to security-team@suse.de.
https://swamp.suse.de/webswamp/wf/64327
Comment 10 Swamp Workflow Management 2019-08-08 13:11:15 UTC
SUSE-SU-2019:2089-1: An update that fixes three vulnerabilities is now available.

Category: security (moderate)
Bug References: 1140738,1141329,1141332
CVE References: CVE-2019-12525,CVE-2019-12529,CVE-2019-13345
Sources used:
SUSE OpenStack Cloud 8 (src):    squid-3.5.21-26.17.1
SUSE OpenStack Cloud 7 (src):    squid-3.5.21-26.17.1
SUSE Linux Enterprise Server for SAP 12-SP3 (src):    squid-3.5.21-26.17.1
SUSE Linux Enterprise Server for SAP 12-SP2 (src):    squid-3.5.21-26.17.1
SUSE Linux Enterprise Server 12-SP4 (src):    squid-3.5.21-26.17.1
SUSE Linux Enterprise Server 12-SP3-LTSS (src):    squid-3.5.21-26.17.1
SUSE Linux Enterprise Server 12-SP3-BCL (src):    squid-3.5.21-26.17.1
SUSE Linux Enterprise Server 12-SP2-LTSS (src):    squid-3.5.21-26.17.1
SUSE Linux Enterprise Server 12-SP2-BCL (src):    squid-3.5.21-26.17.1
SUSE Enterprise Storage 5 (src):    squid-3.5.21-26.17.1
SUSE Enterprise Storage 4 (src):    squid-3.5.21-26.17.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 11 Swamp Workflow Management 2019-08-08 16:10:43 UTC
SUSE-SU-2019:2092-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1140738
CVE References: CVE-2019-13345
Sources used:
SUSE Linux Enterprise Module for Server Applications 15-SP1 (src):    squid-4.8-5.8.1
SUSE Linux Enterprise Module for Server Applications 15 (src):    squid-4.8-5.8.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 12 Swamp Workflow Management 2019-08-17 01:13:35 UTC
SUSE-SU-2019:2089-2: An update that fixes three vulnerabilities is now available.

Category: security (moderate)
Bug References: 1140738,1141329,1141332
CVE References: CVE-2019-12525,CVE-2019-12529,CVE-2019-13345
Sources used:
SUSE OpenStack Cloud Crowbar 8 (src):    squid-3.5.21-26.17.1
SUSE Enterprise Storage 5 (src):    squid-3.5.21-26.17.1
HPE Helion Openstack 8 (src):    squid-3.5.21-26.17.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 13 Swamp Workflow Management 2019-08-20 16:21:19 UTC
openSUSE-SU-2019:1963-1: An update that fixes one vulnerability is now available.

Category: security (moderate)
Bug References: 1140738
CVE References: CVE-2019-13345
Sources used:
openSUSE Leap 15.1 (src):    squid-4.8-lp151.2.3.1
openSUSE Leap 15.0 (src):    squid-4.8-lp150.9.1
Comment 14 Robert Frohl 2019-11-08 15:42:40 UTC
Seems like this needs additional patches, from [0]:

Squid 3.x:
 <http://www.squid-cache.org/Versions/v3/3.5/changesets/squid-3.5-5730c2b5cb56e7639dc423dd62651c8736a54e35.patch>

Squid 4:
 <http://www.squid-cache.org/Versions/v4/changesets/squid-4-be1dc8614e7514103ba84d4067ed6fd15ab8f82e.patch>
 <http://www.squid-cache.org/Versions/v4/changesets/squid-4-5a90b4ce64c346ba7f317a278ba601091d9de076.patch>
[..]

Revision history:

 2019-05-27 13:38:06 UTC Initial Report
 2019-06-05 15:52:17 UTC CVE Assignment
 2019-07-04 01:17:48 UTC Patches Released
 2019-07-12 13:00:00 UTC Advisory Released
 2019-11-03 16:22:22 UTC Additional patch released

[0] http://www.squid-cache.org/Advisories/SQUID-2019_6.txt
Comment 15 Swamp Workflow Management 2019-11-08 17:00:07 UTC
This is an autogenerated message for OBS integration:
This bug (1140738) was mentioned in
https://build.opensuse.org/request/show/746661 Factory / squid
Comment 17 Swamp Workflow Management 2019-11-14 20:14:25 UTC
SUSE-SU-2019:2975-1: An update that fixes 12 vulnerabilities is now available.

Category: security (important)
Bug References: 1133089,1140738,1141329,1141330,1141332,1141442,1156323,1156324,1156326,1156328,1156329
CVE References: CVE-2019-12523,CVE-2019-12525,CVE-2019-12526,CVE-2019-12527,CVE-2019-12529,CVE-2019-12854,CVE-2019-13345,CVE-2019-18676,CVE-2019-18677,CVE-2019-18678,CVE-2019-18679,CVE-2019-3688
Sources used:
SUSE Linux Enterprise Module for Server Applications 15-SP1 (src):    squid-4.9-5.11.1
SUSE Linux Enterprise Module for Server Applications 15 (src):    squid-4.9-5.11.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 18 Swamp Workflow Management 2019-11-21 17:17:17 UTC
openSUSE-SU-2019:2540-1: An update that fixes 12 vulnerabilities is now available.

Category: security (important)
Bug References: 1133089,1140738,1141329,1141330,1141332,1141442,1156323,1156324,1156326,1156328,1156329
CVE References: CVE-2019-12523,CVE-2019-12525,CVE-2019-12526,CVE-2019-12527,CVE-2019-12529,CVE-2019-12854,CVE-2019-13345,CVE-2019-18676,CVE-2019-18677,CVE-2019-18678,CVE-2019-18679,CVE-2019-3688
Sources used:
openSUSE Leap 15.0 (src):    squid-4.9-lp150.13.1
Comment 19 Swamp Workflow Management 2019-11-21 17:20:14 UTC
openSUSE-SU-2019:2541-1: An update that fixes 12 vulnerabilities is now available.

Category: security (important)
Bug References: 1133089,1140738,1141329,1141330,1141332,1141442,1156323,1156324,1156326,1156328,1156329
CVE References: CVE-2019-12523,CVE-2019-12525,CVE-2019-12526,CVE-2019-12527,CVE-2019-12529,CVE-2019-12854,CVE-2019-13345,CVE-2019-18676,CVE-2019-18677,CVE-2019-18678,CVE-2019-18679,CVE-2019-3688
Sources used:
openSUSE Leap 15.1 (src):    squid-4.9-lp151.2.7.1
Comment 20 Swamp Workflow Management 2019-11-26 14:13:11 UTC
SUSE-SU-2019:3067-1: An update that fixes 7 vulnerabilities is now available.

Category: security (important)
Bug References: 1140738,1156323,1156324,1156326,1156328,1156329
CVE References: CVE-2019-12523,CVE-2019-12526,CVE-2019-13345,CVE-2019-18676,CVE-2019-18677,CVE-2019-18678,CVE-2019-18679
Sources used:
SUSE Linux Enterprise Server 12-SP5 (src):    squid-4.9-4.3.2

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 22 Swamp Workflow Management 2020-08-24 16:13:35 UTC
SUSE-SU-2020:14460-1: An update that fixes 21 vulnerabilities is now available.

Category: security (important)
Bug References: 1140738,1141329,1141332,1156323,1156324,1156326,1156328,1156329,1162687,1162689,1162691,1167373,1169659,1170313,1170423,1173304,1173455
CVE References: CVE-2019-12519,CVE-2019-12520,CVE-2019-12521,CVE-2019-12523,CVE-2019-12524,CVE-2019-12525,CVE-2019-12526,CVE-2019-12528,CVE-2019-12529,CVE-2019-13345,CVE-2019-18676,CVE-2019-18677,CVE-2019-18678,CVE-2019-18679,CVE-2019-18860,CVE-2020-11945,CVE-2020-14059,CVE-2020-15049,CVE-2020-8449,CVE-2020-8450,CVE-2020-8517
JIRA References: 
Sources used:
SUSE Linux Enterprise Server 11-SP4-LTSS (src):    squid3-3.1.23-8.16.37.12.1
SUSE Linux Enterprise Point of Sale 11-SP3 (src):    squid3-3.1.23-8.16.37.12.1
SUSE Linux Enterprise Debuginfo 11-SP4 (src):    squid3-3.1.23-8.16.37.12.1

NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
Comment 23 Marcus Meissner 2021-01-17 08:09:03 UTC
done