CVE-2018-19132Missing Release of Resource after Effective Lifetime in Squid

Severity
5.9MEDIUMNVD
EPSS
11.3%
top 6.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 9
Latest updateMay 13

Description

Squid before 4.4, when SNMP is enabled, allows a denial of service (Memory Leak) via an SNMP packet.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 2.2 | Impact: 3.6

Affected Packages2 packages

Debiansquid/squid< 4.4-1+3

Also affects: Debian Linux 8.0

Patches

🔴Vulnerability Details

4
GHSA
GHSA-5vh5-r999-h6wp: Squid before 42022-05-13
OSV
squid, squid3 vulnerabilities2019-07-15
CVEList
CVE-2018-19132: Squid before 42018-11-09
OSV
CVE-2018-19132: Squid before 42018-11-09

📋Vendor Advisories

3
Ubuntu
Squid vulnerabilities2019-07-15
Red Hat
squid: Memory leak in SNMP query rejection code2018-10-31
Debian
CVE-2018-19132: squid - Squid before 4.4, when SNMP is enabled, allows a denial of service (Memory Leak)...2018

💬Community

2
Bugzilla
CVE-2018-19132 squid: Memory leak in SNMP query rejection code2018-11-01
Bugzilla
CVE-2018-19132 squid: Memory leak in SNMP query rejection code [fedora-all]2018-11-01
CVE-2018-19132 — Squid-cache Squid vulnerability | cvebase