CVE-2019-12519
CVSS v3.1
9.8 (Critical)
CVSS v2.0
7.5 (High)
EPSS
1.78 % (88th)
Affected Products
4
Advisories
17
An issue was discovered in Squid through 4.7. When handling the tag esi:when when ESI is enabled, Squid calls ESIExpression::Evaluate. This function uses a fixed stack buffer to hold the expression while it's being evaluated. When processing the expression, it could either evaluate the top of the stack, or add a new member to the stack. When adding a new member, there is no check to ensure that the stack won't overflow.
Weaknesses
- CWE-787
- Out-of-bounds Write
- CVE Status
- PUBLISHED
- CNA
- MITRE
- Published Date
-
2020-04-15 20:15:13
(4 years ago) - Updated Date
-
2021-02-11 14:43:00
(3 years ago)
Affected Products
Loading...
Loading...
Configuration #1
|
Configuration #2
|
Configuration #3
|
Configuration #4
|
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...