CVE-2019-18679 log

Source
Severity Medium
Remote Yes
Type Information disclosure
Description
An information disclosure issue has been found in Squid before 4.9, when processing HTTP Digest Authentication. The nonce tokens contain the raw byte value of a pointer which sits within heap memory allocation, which reduces ASLR protections and may aid attackers isolating memory areas to target for remote code execution attacks.
Group Package Affected Fixed Severity Status Ticket
AVG-1062 squid 4.8-2 4.9-1 Critical Fixed
Date Advisory Group Package Severity Type
07 Nov 2019 ASA-201911-8 AVG-1062 squid Critical multiple issues
References
http://www.squid-cache.org/Advisories/SQUID-2019_11.txt
http://www.squid-cache.org/Versions/v4/changesets/squid-4-671ba97abe929156dc4c717ee52ad22fba0f7443.patc