SB2020041542 - Privilege escalation in Squid
Published: April 15, 2020 Updated: August 6, 2025
Security Bulletin ID
SB2020041542
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Local access
Highest impact
Code execution
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2019-12522)
The vulnerability allows a local user to escalate privileges on the system.
When Squid is run as root, it spawns its child processes as a lesser user, by default the user nobody. This is done via the leave_suid call. leave_suid leaves the Saved UID as 0. This makes it trivial for an attacker who has compromised the child process to escalate their privileges back to root.
Remediation
Install update from vendor's website.