Squid through 4.14 and 5.x through 5.0.5, in some configurations, allows information disclosure because of an out-of-bounds read in WCCP protocol data. This can be leveraged as part of a chain for remote code execution as nobody.
Metrics
CVSS Version: 3.1 |
Base Score: 3.7 LOW Vector: CVSS:3.1/AC:H/AV:N/A:N/C:L/I:N/PR:N/S:U/UI:N