Oval Definition:oval:com.ubuntu.bionic:def:2019186790000000
Revision Date:2019-11-26Version:1
Title:CVE-2019-18679 on Ubuntu 18.04 LTS (bionic) - medium.
Description:An issue was discovered in Squid 2.x, 3.x, and 4.x through 4.8. Due to incorrect data management, it is vulnerable to information disclosure when processing HTTP Digest Authentication. Nonce tokens contain the raw byte value of a pointer that sits within heap memory allocation. This information reduces ASLR protections and may aid attackers isolating memory areas to target for remote code execution attacks.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2019-18679
Platform(s):Ubuntu 18.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 18.04 LTS (bionic) is installed.
  • AND squid3 package in bionic was vulnerable but has been fixed (note: '3.5.27-1ubuntu1.4').
  • BACK