Lucene search

K
redhatcveRedhat.comRH:CVE-2019-12522
HistoryApr 24, 2020 - 9:33 a.m.

CVE-2019-12522

2020-04-2409:33:48
redhat.com
access.redhat.com
14

EPSS

0

Percentile

12.6%

A flaw was found in squid. When Squid is run as root, it spawns its child processes as a lesser user, by default the user nobody. This is done via the leave_suid call. leave_suid leaves the Saved UID as 0. This makes it trivial for an attacker who has compromised the child process to escalate their privileges back to root. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.