Security Advisory

CVE-2019-12526

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2019-11-26 16:41:57
Last updated 2024-08-04 23:24:38
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

An issue was discovered in Squid before 4.9. URN response handling in Squid suffers from a heap-based buffer overflow. When receiving data from a remote server in response to an URN request, Squid fails to ensure that the response can fit within the buffer. This leads to attacker controlled data overflowing in the heap.