CVE-2019-18679
Summary
| CVE | CVE-2019-18679 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-11-26 17:15:00 UTC |
| Updated | 2023-11-07 03:06:00 UTC |
| Description | An issue was discovered in Squid 2.x, 3.x, and 4.x through 4.8. Due to incorrect data management, it is vulnerable to information disclosure when processing HTTP Digest Authentication. Nonce tokens contain the raw byte value of a pointer that sits within heap memory allocation. This information reduces ASLR protections and may aid attackers isolating memory areas to target for remote code execution attacks. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] [DLA 2278-1] squid3 security update |
MLIST |
lists.debian.org |
|
| www.squid-cache.org/Advisories/SQUID-2019_11.txt |
CONFIRM |
www.squid-cache.org |
Third Party Advisory |
| [SECURITY] Fedora 30 Update: squid-4.9-2.fc30 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Mailing List, Third Party Advisory |
| Squid: Multiple vulnerabilities (GLSA 202003-34) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| www.squid-cache.org/Versions/v4/changesets/squid-4-671ba97abe929156dc4c717ee52ad2... |
CONFIRM |
www.squid-cache.org |
Release Notes |
| USN-4213-1: Squid vulnerabilities | Ubuntu security notices | Ubuntu |
UBUNTU |
usn.ubuntu.com |
Third Party Advisory |
| [SECURITY] Fedora 31 Update: squid-4.9-2.fc31 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] [DLA 2028-1] squid3 security update |
MLIST |
lists.debian.org |
Third Party Advisory |
| [SECURITY] Fedora 31 Update: squid-4.9-2.fc31 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Mailing List, Third Party Advisory |
| Debian -- Security Information -- DSA-4682-1 squid |
DEBIAN |
www.debian.org |
|
| Bug 1156324 – VUL-0: CVE-2019-18679: squid,squid3: information disclosure when processing HTTP Digest Authentication |
CONFIRM |
bugzilla.suse.com |
Issue Tracking, Third Party Advisory |
| [SECURITY] Fedora 30 Update: squid-4.9-2.fc30 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Hash Digest noncedata by squidcontrib · Pull Request #491 · squid-cache/squid · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159658 Oracle Enterprise Linux Security Update for squid:4 (ELSA-2020-4743)
- 296075 Oracle Solaris 11.4 Support Repository Update (SRU) 21.69.0 Missing (CPUAPR2020)
- 377360 Alibaba Cloud Linux Security Update for squid:4 (ALINUX3-SA-2022:0124)
- 500664 Alpine Linux Security Update for squid
- 504431 Alpine Linux Security Update for squid
- 670223 EulerOS Security Update for squid (EulerOS-SA-2021-1852)
- 940034 AlmaLinux Security Update for squid:4 (ALSA-2020:4743)
- 960867 Rocky Linux Security Update for squid:4 (RLSA-2020:4743)