peter bassill · operator
$ cve CVE-2019-12526 JSON

CVE-2019-12526

9.8
CRITICAL · CVSS 3.1 · EPSS 20.3% (pctl 97)

Patch early

EPSS 20.3% — above the 10% action threshold.

Description

An issue was discovered in Squid before 4.9. URN response handling in Squid suffers from a heap-based buffer overflow. When receiving data from a remote server in response to an URN request, Squid fails to ensure that the response can fit within the buffer. This leads to attacker controlled data overflowing in the heap.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS20.25% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-787
On CISA KEVno
Public exploitnone known
Published2019-11-26
Last modified2026-06-17

Affected (5)

VendorProduct
canonicalubuntu linux
debiandebian linux
fedoraprojectfedora
opensuseleap
squid-cachesquid

References

→ the Explorer  ·  watch your stack  ·  NVD