ArchLinux: 201907-5: squid: arbitrary code execution
Summary
Due to incorrect buffer management Squid versions prior to 4.8 are vulnerable to a heap overflow and possible remote code execution attack when processing HTTP Authentication credentials.
Resolution
Upgrade to 4.8-1.
# pacman -Syu "squid>=4.8-1"
The problem has been fixed upstream in version 4.8.
References
http://www.squid-cache.org/Advisories/SQUID-2019_5.txt https://security.archlinux.org/CVE-2019-12527
Workaround
None.