CVE-2019-18679
Due to incorrect data management, it is vulnerable to information disclosure when processing HTTP Digest Authentication.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 41.0%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
An issue was discovered in Squid 2.x, 3.x, and 4.x through 4.8. Due to incorrect data management, it is vulnerable to information disclosure when processing HTTP Digest Authentication. Nonce tokens contain the raw byte value of a pointer that sits within heap memory allocation. This information reduces ASLR protections and may aid attackers isolating memory areas to target for remote code execution attacks.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 40.98% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- squid-cache/squid · canonical/ubuntu linux · debian/debian linux · fedoraproject/fedora
- Source
- cve@mitre.org
References
- http://www.squid-cache.org/Advisories/SQUID-2019_11.txtThird Party Advisory
- http://www.squid-cache.org/Versions/v4/changesets/squid-4-671ba97abe929156dc4c717ee52ad22fba0f7443.patchRelease Notes
- https://bugzilla.suse.com/show_bug.cgi?id=1156324Issue Tracking, Third Party Advisory
- https://github.com/squid-cache/squid/pull/491Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/12/msg00011.htmlThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/07/msg00009.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MTM74TU2BSLT5B3H4F3UDW53672NVLMC/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UEMOYTMCCFWK5NOXSXEIH5D2VGWVXR67/
- https://security.gentoo.org/glsa/202003-34
- https://usn.ubuntu.com/4213-1/Third Party Advisory
- https://www.debian.org/security/2020/dsa-4682
- http://www.squid-cache.org/Advisories/SQUID-2019_11.txtThird Party Advisory
- http://www.squid-cache.org/Versions/v4/changesets/squid-4-671ba97abe929156dc4c717ee52ad22fba0f7443.patchRelease Notes
- https://bugzilla.suse.com/show_bug.cgi?id=1156324Issue Tracking, Third Party Advisory
- https://github.com/squid-cache/squid/pull/491Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/12/msg00011.htmlThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/07/msg00009.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MTM74TU2BSLT5B3H4F3UDW53672NVLMC/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UEMOYTMCCFWK5NOXSXEIH5D2VGWVXR67/
- https://security.gentoo.org/glsa/202003-34
- https://usn.ubuntu.com/4213-1/Third Party Advisory
- https://www.debian.org/security/2020/dsa-4682
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.