TROYANOSYVIRUS
Retour aux CVEs

CVE-2019-12526

CRITICAL
9.8

Description

An issue was discovered in Squid before 4.9. URN response handling in Squid suffers from a heap-based buffer overflow. When receiving data from a remote server in response to an URN request, Squid fails to ensure that the response can fit within the buffer. This leads to attacker controlled data overflowing in the heap.

Details CVE

Score CVSS v3.19.8
SeveriteCRITICAL
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie11/26/2019
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0

Produits affectes

canonical:ubuntu_linuxdebian:debian_linuxfedoraproject:fedoraopensuse:leapsquid-cache:squid

Faiblesses (CWE)

CWE-787

References

http://www.squid-cache.org/Advisories/SQUID-2019_7.txt(af854a3a-2127-422b-91ae-364da2661108)
https://bugzilla.suse.com/show_bug.cgi?id=1156326(af854a3a-2127-422b-91ae-364da2661108)
https://security.gentoo.org/glsa/202003-34(af854a3a-2127-422b-91ae-364da2661108)
https://usn.ubuntu.com/4213-1/(af854a3a-2127-422b-91ae-364da2661108)
https://www.debian.org/security/2020/dsa-4682(af854a3a-2127-422b-91ae-364da2661108)

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.