PT-2020-9333 · Squid+2 · Squid+3
Published
2019-07-15
·
Updated
2021-03-10
·
CVE-2019-12522
CVSS v3.1
4.5
Medium
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions:
Squid versions through 4.7
Description:
An issue was discovered in Squid when it is run as root. It spawns its child processes as a lesser user, by default the user nobody, via the
leave suid call. The leave suid call leaves the Saved UID as 0, making it trivial for an attacker who has compromised the child process to escalate their privileges back to root.Recommendations:
For Squid versions through 4.7, consider disabling the
leave suid call as a temporary workaround until a patch is available. Restrict access to the child processes to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Debian
Squid
Squid Cache