CVE-2020-14059Improper Synchronization in Squid

Severity
6.5MEDIUMNVD
EPSS
4.2%
top 11.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 30

Description

An issue was discovered in Squid 5.x before 5.0.3. Due to an Incorrect Synchronization, a Denial of Service can occur when processing objects in an SMP cache because of an Ipc::Mem::PageStack::pop ABA problem during access to the memory page/slot management list.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages1 packages

NVDsquid-cache/squid5.05.0.3

Patches

🔴Vulnerability Details

1
CVEList
CVE-2020-14059: An issue was discovered in Squid 52020-06-30

📋Vendor Advisories

2
Red Hat
squid: DoS when processing objects in an SMP cache due to an incorrect synchronization2020-06-19
Debian
CVE-2020-14059: squid - An issue was discovered in Squid 5.x before 5.0.3. Due to an Incorrect Synchroni...2020

💬Community

2
Bugzilla
CVE-2020-14059 squid: DoS when processing objects in an SMP cache due to an incorrect synchronization [fedora-all]2020-06-30
Bugzilla
CVE-2020-14059 squid: DoS when processing objects in an SMP cache due to an incorrect synchronization2020-06-30
CVE-2020-14059 — Improper Synchronization in Squid | cvebase