Double Free in Squid - #VU50972

 

Double Free in Squid - #VU50972

Published: February 28, 2021


Vulnerability identifier: #VU50972
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-415
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a boundary error when processing "acl" directove. A local user with ability to supply a custom ACL rule for the first and second addresses can trigger a double free error and crash the service or execute arbitrary code with elevated privileges.



Affected software

Squid

Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.


External References

Related Security Bulletins