4.3
CVSSv2

CVE-2018-19132

Published: 09/11/2018 Updated: 11/07/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

Squid prior to 4.4, when SNMP is enabled, allows a denial of service (Memory Leak) via an SNMP packet.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

squid-cache squid

debian debian linux 8.0

Vendor Advisories

Debian Bug report logs - #912294 squid: CVE-2018-19132: SQUID-2018:5: Denial of Service issue in SNMP processing Package: src:squid; Maintainer for src:squid is Luigi Gangitano <luigi@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 29 Oct 2018 21:48:02 UTC Severity: important Tags: secur ...
Several security issues were fixed in Squid ...
A memory leak was discovered in the way Squid handles SNMP denied queries A remote attacker may use this flaw to exhaust the resources on the server machine (CVE-2018-19132) ...
Squid before 44 has XSS via a crafted X509 certificate during HTTP(S) error page generation for certificate errors (CVE-2018-19131) A memory leak was discovered in the way Squid handles SNMP denied queries A remote attacker may use this flaw to exhaust the resources on the server machine (CVE-2018-19132) ...
A memory leak was discovered in the way Squid handles SNMP denied queries A remote attacker may use this flaw to exhaust the resources on the server machine ...