#VU25019 Out-of-bounds read in Squid - CVE-2019-12528
Published: February 7, 2020
Squid
Squid-cache.org
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to a boundary condition when translating FTP server listing into HTTP responses. A remote attacker can trick the victim into vising a specially crafted FTP server, trigger out-of-bounds read and gain access to memory contents of the heap.