Memory leak in Squid - CVE-2018-19132
Published: November 15, 2018
Vulnerability identifier: #VU15903
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-19132
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform denial of service (DoS) attack.
The vulnerability exists due to memory leak when processing SNMP requests. A remote attacker can send a specially crafted SNMP request via the proxy server, trigger excessive consumption of memory resources on the system and denial of service conditions.
Affected software
Squid
Amazon Linux AMI
Opensuse
Fedora
squid
Amazon Linux AMI
Opensuse
Fedora
squid
How to mitigate CVE-2018-19132
Install updates from vendor's website.
Squid - update to 4.4
squid - addressed in versions 4.4-1.fc28, 4.4-1.fc29
squid - addressed in versions 4.4-1.fc28, 4.4-1.fc29