An issue was discovered in Squid before 4.10. It allows a crafted FTP server to trigger disclosure of sensitive information from heap memory, such as information associated with other users sessions or non-Squid processes.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Squid | Squid-cache | * | 4.10 (excluding) |
Red Hat Enterprise Linux 7 | RedHat | squid-7:3.5.20-17.el7_9.4 | * |
Red Hat Enterprise Linux 8 | RedHat | squid:4-8030020200828070549.30b713e6 | * |
Squid | Ubuntu | devel | * |
Squid | Ubuntu | eoan | * |
Squid | Ubuntu | focal | * |
Squid | Ubuntu | groovy | * |
Squid | Ubuntu | hirsute | * |
Squid | Ubuntu | trusty | * |
Squid3 | Ubuntu | bionic | * |
Squid3 | Ubuntu | precise/esm | * |
Squid3 | Ubuntu | trusty | * |
Squid3 | Ubuntu | xenial | * |