ISOMAN

CVE

CVE-2019-12854

Due to incorrect string termination, Squid cachemgr.cgi 4.0 through 4.7 may access unallocated memory. On systems with memory access protections, this can cause the CGI process to terminate unexpectedly, resulting in a denial of service for all clients using it.

Severity
HIGH
CVSS
7.5
Published
Modified

Linked Releases

DistributionReleaseStatusEvidence
Ubuntu18.04.6 amd64 desktopunknownsource
Ubuntu18.04.6 amd64 live-serverunknownsource

References

  1. http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00053.html
  2. http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00056.html
  3. http://www.squid-cache.org/Advisories/SQUID-2019_1.txt
  4. http://www.squid-cache.org/Versions/v4/changesets/squid-4-2981a957716c61ff7e21eee1d7d6eb5a237e466d.patch
  5. https://bugs.squid-cache.org/show_bug.cgi?id=4937
  6. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPXN2CLAGN5QSQBTOV5IGVLDOQSRFNTZ/
  7. https://seclists.org/bugtraq/2019/Aug/42
  8. https://usn.ubuntu.com/4213-1/
  9. https://www.debian.org/security/2019/dsa-4507
  10. http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00053.html
  11. http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00056.html
  12. http://www.squid-cache.org/Advisories/SQUID-2019_1.txt
  13. http://www.squid-cache.org/Versions/v4/changesets/squid-4-2981a957716c61ff7e21eee1d7d6eb5a237e466d.patch
  14. https://bugs.squid-cache.org/show_bug.cgi?id=4937
  15. https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPXN2CLAGN5QSQBTOV5IGVLDOQSRFNTZ/
  16. https://seclists.org/bugtraq/2019/Aug/42
  17. https://usn.ubuntu.com/4213-1/
  18. https://www.debian.org/security/2019/dsa-4507