V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2019-12854
DEB
Medium

Due to incorrect string termination, Squid cachemgr.cgi 4.0 through 4.7 may access unallocated memory. On systems with memory access protec…

CVSS
4.3
Medium
EPSS
0.38
p97
Published
2019-01-01
Updated
2019-01-01
Description

Due to incorrect string termination, Squid cachemgr.cgi 4.0 through 4.7 may access unallocated memory. On systems with memory access protections, this can cause the CGI process to terminate unexpectedly, resulting in a denial of service for all clients using it.

Tags · CWE
CWE-400
CAPEC-147
CAPEC-227
CAPEC-492
Affected products
Debian_linuxFedora
CVSS vector
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Timeline
2019-01-01
Published
2019-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: A
Adjacent Network (A)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: N
None (N)
Availability Impact
A: L
Low (L)
Exploit indicators
EPSS
0.380 · p97
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-227 · CWE-400
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected software
ProductVendorStatus
squidTracked
squidTracked
squidTracked
squidTracked
squid3Tracked
squid3Tracked
squid3Tracked
debian_linux*Tracked
fedora*Tracked
leap*Tracked
squid*Tracked
ubuntu_linux*Tracked
Source databases
DEB
CVE
RED
UBU
Related vulnerabilities