CentOS Linux 6 [TuxCare] Security Update: squid34 Multiple Vulnerabilities (CENTOS6:CLSA-2026:1777541147)

critical Nessus Plugin ID 361595

Synopsis

The CentOS Linux host is missing one or more security updates.

Description

The CentOS Linux 6 host has a package installed that is affected by multiple vulnerabilities as referenced in the TuxCare CENTOS6:CLSA-2026:1777541147 advisory.

- The Squid Software Foundation Squid HTTP Caching Proxy version prior to version 4.0.23 contains a NULL Pointer Dereference vulnerability in HTTP Response X-Forwarded-For header processing that can result in Denial of Service to all clients of the proxy. This attack appear to be exploitable via Remote HTTP server responding with an X-Forwarded-For header to certain types of HTTP request. This vulnerability appears to have been fixed in 4.0.23 and later. (CVE-2018-1000027)

- Squid before 4.4 has XSS via a crafted X.509 certificate during HTTP(S) error page generation for certificate errors. (CVE-2018-19131)

- Squid before 4.4, when SNMP is enabled, allows a denial of service (Memory Leak) via an SNMP packet.
(CVE-2018-19132)

- An issue was discovered in Squid before 4.9. When handling a URN request, a corresponding HTTP request is made. This HTTP request doesn't go through the access checks that incoming HTTP requests go through. This causes all access checks to be bypassed and allows access to restricted HTTP servers, e.g., an attacker can connect to HTTP servers that only listen on localhost. (CVE-2019-12523)

- An issue was discovered in Squid 3.3.9 through 3.5.28 and 4.x through 4.7. When Squid is configured to use Digest authentication, it parses the header Proxy-Authorization. It searches for certain tokens such as domain, uri, and qop. Squid checks if this token's value starts with a quote and ends with one. If so, it performs a memcpy of its length minus 2. Squid never checks whether the value is just a single quote (which would satisfy its requirements), leading to a memcpy of its length minus 1. (CVE-2019-12525)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected squid34 package based on the guidance in TuxCare advisory CENTOS6:CLSA-2026:1777541147.

See Also

https://cve.tuxcare.com/els/releases/CLSA-2026:1777541147

http://www.nessus.org/u?3fc3d74c

Plugin Details

Severity: Critical

ID: 361595

File Name: tuxcare_centos_6_CLSA-2026-1777541147.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 10/1/2026

Updated: 10/1/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.12

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2019-12525

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Required KB Items: Host/local_checks_enabled, Host/CentOS/release, Host/CentOS/rpm-list, Host/OS/extended-third-party

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 4/30/2026

Vulnerability Publication Date: 1/23/2018

Reference Information

CVE: CVE-2018-1000027, CVE-2018-19131, CVE-2018-19132, CVE-2019-12523, CVE-2019-12525, CVE-2019-12528, CVE-2019-12529, CVE-2019-13345, CVE-2019-18677, CVE-2019-18678, CVE-2019-18679, CVE-2019-18860

CLSA: 2026:1777541147