CVE Vulnerabilities

CVE-2019-12854

Published: Aug 15, 2019 | Modified: Nov 07, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
4.3 MODERATE
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Ubuntu
LOW

Due to incorrect string termination, Squid cachemgr.cgi 4.0 through 4.7 may access unallocated memory. On systems with memory access protections, this can cause the CGI process to terminate unexpectedly, resulting in a denial of service for all clients using it.

Affected Software

Name Vendor Start Version End Version
Squid Squid-cache 4.0 (including) 4.7 (including)
Red Hat Enterprise Linux 8 RedHat squid:4-8030020200828070549.30b713e6 *
Squid Ubuntu disco *
Squid Ubuntu upstream *

References