An issue was discovered in Squid 2.x, 3.x, and 4.x through 4.8. Due to incorrect data management, it is vulnerable to information disclosure when processing HTTP Digest Authentication. Nonce tokens contain the raw byte value of a pointer that sits within heap memory allocation. This information reduces ASLR protections and may aid attackers isolating memory areas to target for remote code execution attacks.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2019-11-26T16:14:03

Updated: 2020-07-10T23:06:12

Reserved: 2019-11-04T00:00:00


Link: CVE-2019-18679

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2019-11-26T17:15:13.047

Modified: 2023-11-07T03:06:53.993


Link: CVE-2019-18679

JSON object: View

cve-icon Redhat Information

No data.

CWE