Wind River Support Network

HomeDefectsLIN8-11827
Fixed

LIN8-11827 : Security Advisory - squid - CVE-2019-12526

Created: Nov 29, 2019    Updated: Jul 1, 2020
Resolved Date: Jun 23, 2020
Found In Version: 8.0.0.1
Fix Version: 8.0.0.34
Severity: Standard
Applicable for: Wind River Linux 8
Component/s: Userspace

Description

An issue was discovered in Squid before 4.9. URN response handling in Squid suffers from a heap-based buffer overflow. When receiving data from a remote server in response to an URN request, Squid fails to ensure that the response can fit within the buffer. This leads to attacker controlled data overflowing in the heap.

CREATE(Triage):(User=admin) [CVE-2019-12526|https://nvd.nist.gov/vuln/detail/CVE-2019-12526]

CVEs


Live chat
Online