CVE-2019-12528: High severity IBM Security Guardium vulnerability
An issue was discovered in Squid before 4.10. It allows a crafted FTP server to trigger disclosure of sensitive information from heap memory, such as information associated with other users' sessions or non-Squid processes.
Other sources
Squid could allow a remote attacker to obtain sensitive information, caused by incorrect data management when translating FTP server listings into HTTP responses. By sending a specially-crafted request, an attacker could exploit this vulnerability to obtain user sessions or non-Squid processes information, and use this information to launch further attacks against the affected system.
— IBM
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/squidto a version that resolves this vulnerability.Fixed in 4.13-10+deb11u3Fixed in 4.13-10+deb11u6Fixed in 5.7-2+deb12u5Fixed in 5.7-2+deb12u4Fixed in 6.13-2+deb13u2Fixed in 7.6-2 - Upgrade
Upgrade
Squidto a version that resolves this vulnerability.Fixed in 4.10
Event History
Frequently Asked Questions
What is CVE-2019-12528?
CVE-2019-12528 is a vulnerability in Squid that allows a crafted FTP server to trigger disclosure of sensitive information.
How severe is CVE-2019-12528?
CVE-2019-12528 has a severity level of 7.5 (high).
Which software versions are affected by CVE-2019-12528?
The affected software versions include Squid 4.6-1+deb10u7, 4.6-1+deb10u8, 4.13-10+deb11u2, 5.7-2, and 6.3-1.
How can I fix CVE-2019-12528?
To fix CVE-2019-12528, update Squid to version 4.10 or later.
Where can I find more information about CVE-2019-12528?
You can find more information about CVE-2019-12528 at the following references: http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00012.html, http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00010.html, http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00018.html