Due to incorrect string termination, Squid cachemgr.cgi 4.0 through 4.7 may access unallocated memory. On systems with memory access protections, this can cause the CGI process to terminate unexpectedly, resulting in a denial of service for all clients using it.
Link | Tags |
---|---|
http://www.squid-cache.org/Advisories/SQUID-2019_1.txt | vendor advisory |
https://bugs.squid-cache.org/show_bug.cgi?id=4937 | vendor advisory |
http://www.squid-cache.org/Versions/v4/changesets/squid-4-2981a957716c61ff7e21eee1d7d6eb5a237e466d.patch | patch vendor advisory |
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPXN2CLAGN5QSQBTOV5IGVLDOQSRFNTZ/ | |
https://www.debian.org/security/2019/dsa-4507 | third party advisory vendor advisory |
https://seclists.org/bugtraq/2019/Aug/42 | third party advisory mailing list |
http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00053.html | vendor advisory mailing list third party advisory |
http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00056.html | vendor advisory mailing list third party advisory |
https://usn.ubuntu.com/4213-1/ | third party advisory vendor advisory |