ISOMAN

CVE

CVE-2019-18860

Squid before 4.9, when certain web browsers are used, mishandles HTML in the host (aka hostname) parameter to cachemgr.cgi.

Severity
MEDIUM
CVSS
6.1
Published
Modified

Linked Releases

References

  1. http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00018.html
  2. https://github.com/squid-cache/squid/pull/504
  3. https://github.com/squid-cache/squid/pull/505
  4. https://lists.debian.org/debian-lts-announce/2020/07/msg00009.html
  5. https://usn.ubuntu.com/4356-1/
  6. https://www.debian.org/security/2020/dsa-4732
  7. http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00018.html
  8. http://www.openwall.com/lists/oss-security/2025/11/04/7
  9. http://www.openwall.com/lists/oss-security/2025/11/05/1
  10. http://www.openwall.com/lists/oss-security/2025/11/05/7
  11. https://github.com/squid-cache/squid/pull/504
  12. https://github.com/squid-cache/squid/pull/505
  13. https://lists.debian.org/debian-lts-announce/2020/07/msg00009.html
  14. https://usn.ubuntu.com/4356-1/
  15. https://www.debian.org/security/2020/dsa-4732