7.5

CVE-2019-18679

An issue was discovered in Squid 2.x, 3.x, and 4.x through 4.8. Due to incorrect data management, it is vulnerable to information disclosure when processing HTTP Digest Authentication. Nonce tokens contain the raw byte value of a pointer that sits within heap memory allocation. This information reduces ASLR protections and may aid attackers isolating memory areas to target for remote code execution attacks.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Squid-cache ≫ Squid Version >= 2.0 <= 2.7
Squid-cache ≫ Squid Version >= 3.0 <= 3.5.28
Squid-cache ≫ Squid Version >= 4.0 <= 4.8
Squid-cache ≫ Squid Version 2.7 Update stable2
Squid-cache ≫ Squid Version 2.7 Update stable3
Squid-cache ≫ Squid Version 2.7 Update stable4
Squid-cache ≫ Squid Version 2.7 Update stable5
Squid-cache ≫ Squid Version 2.7 Update stable6
Squid-cache ≫ Squid Version 2.7 Update stable7
Squid-cache ≫ Squid Version 2.7 Update stable8
Squid-cache ≫ Squid Version 2.7 Update stable9
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 19.04
Canonical ≫ Ubuntu Linux Version 19.10
Debian ≫ Debian Linux Version 8.0
Fedoraproject ≫ Fedora Version 30
Fedoraproject ≫ Fedora Version 31
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 40.98% 0.985
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

https://lists.debian.org/debian-lts-announce/2020/07/msg00009.html
https://usn.ubuntu.com/4213-1/
Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MTM74TU2BSLT5B3H4F3UDW53672NVLMC/
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UEMOYTMCCFWK5NOXSXEIH5D2VGWVXR67/
https://www.debian.org/security/2020/dsa-4682
https://lists.debian.org/debian-lts-announce/2019/12/msg00011.html
Third Party Advisory
https://security.gentoo.org/glsa/202003-34
http://www.squid-cache.org/Versions/v4/changesets/squid-4-671ba97abe929156dc4c717ee52ad22fba0f7443.patch
Release Notes
http://www.squid-cache.org/Advisories/SQUID-2019_11.txt
Third Party Advisory
https://bugzilla.suse.com/show_bug.cgi?id=1156324
Third Party Advisory
Issue Tracking
https://github.com/squid-cache/squid/pull/491
Patch
Third Party Advisory