Squid Buffer Copy without Checking Size of Input (Classic Buffer Overflow) Vulnerability - CVE-2019-12526 - Vulnerability Database

Squid Buffer Copy without Checking Size of Input (Classic Buffer Overflow) Vulnerability - CVE-2019-12526

Critical
Reference: CVE-2019-12526
Title: Squid Buffer Copy without Checking Size of Input (Classic Buffer Overflow) Vulnerability
Overview:

An issue was discovered in Squid before 4.9. URN response handling in Squid suffers from a heap-based buffer overflow. When receiving data from a remote server in response to an URN request Squid fails to ensure that the response can fit within the buffer. This leads to attacker controlled data overflowing in the heap.