#VU20461 Out-of-bounds read in Squid - CVE-2019-12854
Published: August 29, 2019
Squid
Squid-cache.org
Description
The vulnerability allows a remote attacker to perform denial of service (DoS) attack.
The vulnerability exists due to a boundary condition when terminating strings in cachemgr.cgi. A remote attacker can a specially crafted request to the affected proxy server, trigger out-of-bounds read error and crash the CGI process, denying access to all users on systems with memory access protections.
Remediation
External links
- http://www.squid-cache.org/Advisories/SQUID-2019_1.txt
- http://www.squid-cache.org/Versions/v4/changesets/squid-4-2981a957716c61ff7e21eee1d7d6eb5a237e466d.patch
- https://bugs.squid-cache.org/show_bug.cgi?id=4937
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SPXN2CLAGN5QSQBTOV5IGVLDOQSRFNTZ/
- https://seclists.org/bugtraq/2019/Aug/42