CVE Vulnerabilities

CVE-2019-12854

Published: Aug 15, 2019 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
4.3 MODERATE
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Due to incorrect string termination, Squid cachemgr.cgi 4.0 through 4.7 may access unallocated memory. On systems with memory access protections, this can cause the CGI process to terminate unexpectedly, resulting in a denial of service for all clients using it.

Affected Software

NameVendorStart VersionEnd Version
SquidSquid-cache4.0 (including)4.7 (including)
Red Hat Enterprise Linux 8RedHatsquid:4-8030020200828070549.30b713e6*
SquidUbuntudisco*
SquidUbuntuupstream*

References