Oval Definition:oval:com.ubuntu.xenial:def:2019186790000000
Revision Date:2019-11-26Version:1
Title:CVE-2019-18679 on Ubuntu 16.04 LTS (xenial) - medium.
Description:An issue was discovered in Squid 2.x, 3.x, and 4.x through 4.8. Due to incorrect data management, it is vulnerable to information disclosure when processing HTTP Digest Authentication. Nonce tokens contain the raw byte value of a pointer that sits within heap memory allocation. This information reduces ASLR protections and may aid attackers isolating memory areas to target for remote code execution attacks.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2019-18679
Platform(s):Ubuntu 16.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 16.04 LTS (xenial) is installed.
  • AND squid3 package in xenial was vulnerable but has been fixed (note: '3.5.12-1ubuntu7.9').
  • BACK