Vulnerability Description
Due to incorrect string termination, Squid cachemgr.cgi 4.0 through 4.7 may access unallocated memory. On systems with memory access protections, this can cause the CGI process to terminate unexpectedly, resulting in a denial of service for all clients using it.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Squid-Cache | Squid | >= 4.0, <= 4.7 |
| Debian | Debian Linux | 10.0 |
| Fedoraproject | Fedora | 29 |
| Canonical | Ubuntu Linux | 16.04 |
| Opensuse | Leap | 15.0 |
References
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00053.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00056.htmlMailing ListThird Party Advisory
- http://www.squid-cache.org/Advisories/SQUID-2019_1.txtVendor Advisory
- http://www.squid-cache.org/Versions/v4/changesets/squid-4-2981a957716c61ff7e21eePatchVendor Advisory
- https://bugs.squid-cache.org/show_bug.cgi?id=4937Vendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://seclists.org/bugtraq/2019/Aug/42Mailing ListThird Party Advisory
- https://usn.ubuntu.com/4213-1/Third Party Advisory
- https://www.debian.org/security/2019/dsa-4507Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00053.htmlMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00056.htmlMailing ListThird Party Advisory
- http://www.squid-cache.org/Advisories/SQUID-2019_1.txtVendor Advisory
- http://www.squid-cache.org/Versions/v4/changesets/squid-4-2981a957716c61ff7e21eePatchVendor Advisory
- https://bugs.squid-cache.org/show_bug.cgi?id=4937Vendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
FAQ
What is CVE-2019-12854?
CVE-2019-12854 is a vulnerability with a CVSS score of 7.5 (HIGH). Due to incorrect string termination, Squid cachemgr.cgi 4.0 through 4.7 may access unallocated memory. On systems with memory access protections, this can cause the CGI process to terminate unexpected...
How severe is CVE-2019-12854?
CVE-2019-12854 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-12854?
Check the references section above for vendor advisories and patch information. Affected products include: Squid-Cache Squid, Debian Debian Linux, Fedoraproject Fedora, Canonical Ubuntu Linux, Opensuse Leap.