CVE-2020-8517: Canonical Ubuntu Linux
High severity, CVSS 7.5. EPSS: 6.8% chance of exploitation in the next 30 days.
An issue was discovered in Squid before 4.10. Due to incorrect input validation, the NTLM authentication credentials parser in ext_lm_group_acl may write to memory outside the credentials buffer. On systems with memory access protections, this can result in the helper process being terminated unexpectedly. This leads to the Squid process also terminating and a denial of service for all clients using the proxy.
Affected products
- Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 19.10 only
- Opensuse Leap: version 15.1 only
- Squid-Cache Squid: before 4.10 (fixed in 4.10)
Published 2020-02-04. Last modified 2026-06-17.