Memory leak in Squid - CVE-2018-19132

 

Memory leak in Squid - CVE-2018-19132

Published: November 15, 2018


Vulnerability identifier: #VU15903
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-19132
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform denial of service (DoS) attack.
The vulnerability exists due to memory leak when processing SNMP requests. A remote attacker can send a specially crafted SNMP request via the proxy server, trigger excessive consumption of memory resources on the system and denial of service conditions.

Affected software

Squid
Amazon Linux AMI
Opensuse
Fedora
squid

How to mitigate CVE-2018-19132

Install updates from vendor's website.

Squid - update to 4.4
squid - addressed in versions 4.4-1.fc28, 4.4-1.fc29

External References

Related Security Bulletins