CVE-2019-12854: Canonical Ubuntu Linux

High severity, CVSS 7.5. EPSS: 11.7% chance of exploitation in the next 30 days.

Due to incorrect string termination, Squid cachemgr.cgi 4.0 through 4.7 may access unallocated memory. On systems with memory access protections, this can cause the CGI process to terminate unexpectedly, resulting in a denial of service for all clients using it.

Affected products

  • Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 19.04 only; version 19.10 only
  • Debian Debian Linux: version 10.0 only
  • Fedoraproject Fedora: version 29 only
  • Opensuse Leap: version 15.0 only; version 15.1 only
  • Squid-Cache Squid: from 4.0, up to and including 4.7

Published 2019-08-15. Last modified 2026-06-17.