CVE-2019-12528Sensitive Information Exposure in Squid

Severity
7.5HIGHNVD
EPSS
23.6%
top 4.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 4
Latest updateMay 24

Description

An issue was discovered in Squid before 4.10. It allows a crafted FTP server to trigger disclosure of sensitive information from heap memory, such as information associated with other users' sessions or non-Squid processes.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

NVDsquid-cache/squid< 4.10
Debiansquid/squid< 4.10-1+3
NVDopensuse/leap15.1

Also affects: Debian Linux 10.0, 9.0, Fedora 30, 31, Ubuntu Linux 16.04, 18.04, 19.10

🔴Vulnerability Details

4
GHSA
GHSA-pjg3-3q79-q39r: An issue was discovered in Squid before 42022-05-24
OSV
squid, squid3 vulnerabilities2020-02-20
CVEList
CVE-2019-12528: An issue was discovered in Squid before 42020-02-04
OSV
CVE-2019-12528: An issue was discovered in Squid before 42020-02-04

📋Vendor Advisories

3
Ubuntu
Squid vulnerabilities2020-02-20
Red Hat
squid: Information Disclosure issue in FTP Gateway2020-02-02
Debian
CVE-2019-12528: squid - An issue was discovered in Squid before 4.10. It allows a crafted FTP server to ...2019

💬Community

3
HackerOne
Squid leaks previous content from reusable buffer2021-08-26
Bugzilla
CVE-2019-12528 squid: Information Disclosure issue in FTP Gateway2020-02-05
Bugzilla
CVE-2019-12528 squid: Information Disclosure issue in FTP Gateway [fedora-all]2020-02-05
CVE-2019-12528 — Sensitive Information Exposure | cvebase