Double Free in Squid - #VU50972
Published: February 28, 2021
Squid
Squid-cache.org
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a boundary error when processing "acl" directove. A local user with ability to supply a custom ACL rule for the first and second addresses can trigger a double free error and crash the service or execute arbitrary code with elevated privileges.