Description
An issue was discovered in Squid 4.0.23 through 4.7. When checking Basic Authentication with HttpHeader::getAuth, Squid uses a global buffer to store the decoded data. Squid does not check that the decoded length isn't greater than the buffer, leading to a heap-based buffer overflow with user controlled data.
Remediation
References
Related Vulnerabilities
WordPress Plugin SEO by Squirrly SEO Multiple Unspecified Vulnerabilities (6.1.4)
WordPress Plugin Smooth Slider SQL Injection (2.6.5)
Envoy Proxy NULL Pointer Dereference Vulnerability (CVE-2021-43824)
phpMyFAQ Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2011-4825)
WordPress Plugin 10Web Social Feed for Instagram Security Bypass (1.3.18)