Логотип exploitDog
bind:"GHSA-4h4q-q4v8-2vq3" OR bind:"CVE-2019-18679"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-4h4q-q4v8-2vq3" OR bind:"CVE-2019-18679"

Количество 14

Количество 14

github логотип

GHSA-4h4q-q4v8-2vq3

около 3 лет назад

An issue was discovered in Squid 2.x, 3.x, and 4.x through 4.8. Due to incorrect data management, it is vulnerable to information disclosure when processing HTTP Digest Authentication. Nonce tokens contain the raw byte value of a pointer that sits within heap memory allocation. This information reduces ASLR protections and may aid attackers isolating memory areas to target for remote code execution attacks.

EPSS: Средний
ubuntu логотип

CVE-2019-18679

больше 5 лет назад

An issue was discovered in Squid 2.x, 3.x, and 4.x through 4.8. Due to incorrect data management, it is vulnerable to information disclosure when processing HTTP Digest Authentication. Nonce tokens contain the raw byte value of a pointer that sits within heap memory allocation. This information reduces ASLR protections and may aid attackers isolating memory areas to target for remote code execution attacks.

CVSS3: 7.5
EPSS: Средний
redhat логотип

CVE-2019-18679

больше 5 лет назад

An issue was discovered in Squid 2.x, 3.x, and 4.x through 4.8. Due to incorrect data management, it is vulnerable to information disclosure when processing HTTP Digest Authentication. Nonce tokens contain the raw byte value of a pointer that sits within heap memory allocation. This information reduces ASLR protections and may aid attackers isolating memory areas to target for remote code execution attacks.

CVSS3: 5.9
EPSS: Средний
nvd логотип

CVE-2019-18679

больше 5 лет назад

An issue was discovered in Squid 2.x, 3.x, and 4.x through 4.8. Due to incorrect data management, it is vulnerable to information disclosure when processing HTTP Digest Authentication. Nonce tokens contain the raw byte value of a pointer that sits within heap memory allocation. This information reduces ASLR protections and may aid attackers isolating memory areas to target for remote code execution attacks.

CVSS3: 7.5
EPSS: Средний
debian логотип

CVE-2019-18679

больше 5 лет назад

An issue was discovered in Squid 2.x, 3.x, and 4.x through 4.8. Due to ...

CVSS3: 7.5
EPSS: Средний
fstec логотип

BDU:2021-01719

больше 5 лет назад

Уязвимость механизма HTTP дайджест-аутентификации прокси-сервера Squid, связанная с раскрытием информации, позволяющая нарушителю получить доступ к конфиденциальным данным

CVSS3: 7.5
EPSS: Средний
suse-cvrf логотип

SUSE-SU-2019:3067-1

больше 5 лет назад

Security update for squid

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:0661-1

больше 5 лет назад

Security update for squid

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:2541-1

больше 5 лет назад

Security update for squid

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:2540-1

больше 5 лет назад

Security update for squid

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:2975-1

больше 5 лет назад

Security update for squid

EPSS: Низкий
rocky логотип

RLSA-2020:4743

больше 4 лет назад

Moderate: squid:4 security, bug fix, and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2020-4743

больше 4 лет назад

ELSA-2020-4743: squid:4 security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:14460-1

почти 5 лет назад

Security update for squid3

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-4h4q-q4v8-2vq3

An issue was discovered in Squid 2.x, 3.x, and 4.x through 4.8. Due to incorrect data management, it is vulnerable to information disclosure when processing HTTP Digest Authentication. Nonce tokens contain the raw byte value of a pointer that sits within heap memory allocation. This information reduces ASLR protections and may aid attackers isolating memory areas to target for remote code execution attacks.

68%
Средний
около 3 лет назад
ubuntu логотип
CVE-2019-18679

An issue was discovered in Squid 2.x, 3.x, and 4.x through 4.8. Due to incorrect data management, it is vulnerable to information disclosure when processing HTTP Digest Authentication. Nonce tokens contain the raw byte value of a pointer that sits within heap memory allocation. This information reduces ASLR protections and may aid attackers isolating memory areas to target for remote code execution attacks.

CVSS3: 7.5
68%
Средний
больше 5 лет назад
redhat логотип
CVE-2019-18679

An issue was discovered in Squid 2.x, 3.x, and 4.x through 4.8. Due to incorrect data management, it is vulnerable to information disclosure when processing HTTP Digest Authentication. Nonce tokens contain the raw byte value of a pointer that sits within heap memory allocation. This information reduces ASLR protections and may aid attackers isolating memory areas to target for remote code execution attacks.

CVSS3: 5.9
68%
Средний
больше 5 лет назад
nvd логотип
CVE-2019-18679

An issue was discovered in Squid 2.x, 3.x, and 4.x through 4.8. Due to incorrect data management, it is vulnerable to information disclosure when processing HTTP Digest Authentication. Nonce tokens contain the raw byte value of a pointer that sits within heap memory allocation. This information reduces ASLR protections and may aid attackers isolating memory areas to target for remote code execution attacks.

CVSS3: 7.5
68%
Средний
больше 5 лет назад
debian логотип
CVE-2019-18679

An issue was discovered in Squid 2.x, 3.x, and 4.x through 4.8. Due to ...

CVSS3: 7.5
68%
Средний
больше 5 лет назад
fstec логотип
BDU:2021-01719

Уязвимость механизма HTTP дайджест-аутентификации прокси-сервера Squid, связанная с раскрытием информации, позволяющая нарушителю получить доступ к конфиденциальным данным

CVSS3: 7.5
68%
Средний
больше 5 лет назад
suse-cvrf логотип
SUSE-SU-2019:3067-1

Security update for squid

больше 5 лет назад
suse-cvrf логотип
SUSE-SU-2020:0661-1

Security update for squid

больше 5 лет назад
suse-cvrf логотип
openSUSE-SU-2019:2541-1

Security update for squid

больше 5 лет назад
suse-cvrf логотип
openSUSE-SU-2019:2540-1

Security update for squid

больше 5 лет назад
suse-cvrf логотип
SUSE-SU-2019:2975-1

Security update for squid

больше 5 лет назад
rocky логотип
RLSA-2020:4743

Moderate: squid:4 security, bug fix, and enhancement update

больше 4 лет назад
oracle-oval логотип
ELSA-2020-4743

ELSA-2020-4743: squid:4 security, bug fix, and enhancement update (MODERATE)

больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2020:14460-1

Security update for squid3

почти 5 лет назад

Уязвимостей на страницу