Due to incorrect string termination, Squid cachemgr.cgi 4.0 through 4.7 may access unallocated memory. On systems with memory access protections, this can cause the CGI process to terminate unexpectedly, resulting in a denial of service for all clients using it.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade libecapUpgrade libecap-devel | May 4, 2022 | Aug 15, 2019 |
| Centos_linux | — | Upgrade squidUpgrade libecap-develUpgrade libecap-debuginfoUpgrade squid-debugsourceUpgrade squid-debuginfoUpgrade libecap-debugsourceUpgrade libecap | Nov 5, 2020 | Aug 15, 2019 |
| Debian | — | Upgrade squid | Sep 3, 2019 | Aug 15, 2019 |
| Huawei Euleros 2_0_sp8 | — | Upgrade squid | Sep 30, 2019 | Aug 15, 2019 |
| Oracle_linux | — | Upgrade squidUpgrade libecapUpgrade libecap-devel | Jul 22, 2024 | Jul 12, 2019 |
| Redhat_linux | — | Upgrade squidUpgrade libecap-develUpgrade squid-debuginfoUpgrade libecap-debugsourceUpgrade libecap-debuginfoUpgrade libecapUpgrade squid-debugsource | Nov 5, 2020 | Aug 15, 2019 |
| Rocky_linux | — | Upgrade libecap-debuginfoUpgrade libecap-develUpgrade libecapUpgrade libecap-debugsource | Mar 12, 2024 | Aug 15, 2019 |
| Suse | — | Upgrade squid | Nov 23, 2019 | Aug 15, 2019 |
| Ubuntu | — | Upgrade squidUpgrade squid3 | Dec 5, 2019 | Aug 15, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub