UBUNTU-CVE-2019-12519
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-12519
UBUNTU-CVE-2019-12519
Summary:
Details: An issue was discovered in Squid through 4.7. When handling the tag esi:when when ESI is enabled, Squid calls ESIExpression::Evaluate. This function uses a fixed stack buffer to hold the expression while it's being evaluated. When processing the expression, it could either evaluate the top of the stack, or add a new member to the stack. When adding a new member, there is no check to ensure that the stack won't overflow.
References: https://ubuntu.com/security/CVE-2019-12519, https://gitlab.com/jeriko.one/security/-/blob/master/squid/CVEs/CVE-2019-12519.txt, http://www.squid-cache.org/Advisories/SQUID-2019_12.txt, https://ubuntu.com/security/notices/USN-4356-1, https://www.cve.org/CVERecord?id=CVE-2019-12519
Affected packages
Package
Name: squid3
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
