CVE-2019-12854
Summary
| CVE | CVE-2019-12854 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-08-15 17:15:00 UTC |
| Updated | 2023-11-07 03:03:00 UTC |
| Description | Due to incorrect string termination, Squid cachemgr.cgi 4.0 through 4.7 may access unallocated memory. On systems with memory access protections, this can cause the CGI process to terminate unexpectedly, resulting in a denial of service for all clients using it. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Canonical | Ubuntu Linux | 16.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 18.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 19.04 | All | All | All |
| Operating System | Canonical | Ubuntu Linux | 19.10 | All | All | All |
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Fedoraproject | Fedora | 29 | All | All | All |
| Operating System | Fedoraproject | Fedora | 29 | All | All | All |
| Operating System | Opensuse | Leap | 15.0 | All | All | All |
| Operating System | Opensuse | Leap | 15.1 | All | All | All |
| Application | Squid-cache | Squid | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Bug 4937 – cachemgr.cgi: unallocated memory access after base64_decode_update | MISC | bugs.squid-cache.org | Vendor Advisory |
| www.squid-cache.org/Advisories/SQUID-2019_1.txt | MISC | www.squid-cache.org | Vendor Advisory |
| [security-announce] openSUSE-SU-2019:2540-1: important: Security update | SUSE | lists.opensuse.org | |
| Bugtraq: [SECURITY] [DSA 4507-1] squid security update | BUGTRAQ | seclists.org | Third Party Advisory |
| USN-4213-1: Squid vulnerabilities | Ubuntu security notices | Ubuntu | UBUNTU | usn.ubuntu.com | |
| [SECURITY] Fedora 29 Update: squid-4.8-2.fc29 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 29 Update: squid-4.8-2.fc29 - package-announce - Fedora Mailing-Lists | CONFIRM | lists.fedoraproject.org | Mailing List, Third Party Advisory |
| www.squid-cache.org/Versions/v4/changesets/squid-4-2981a957716c61ff7e21eee1d7d6eb... | MISC | www.squid-cache.org | Patch, Vendor Advisory |
| [security-announce] openSUSE-SU-2019:2541-1: important: Security update | SUSE | lists.opensuse.org | |
| Debian -- Security Information -- DSA-4507-1 squid | DEBIAN | www.debian.org | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.