PublicDateAtUSN: 2020-03-20 21:15:00 UTC Candidate: CVE-2019-18860 PublicDate: 2020-03-20 21:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-18860 https://ubuntu.com/security/notices/USN-4356-1 Description: Squid before 4.9, when certain web browsers are used, mishandles HTML in the host (aka hostname) parameter to cachemgr.cgi. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: low Discovered-by: Assigned-to: mdeslaur CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N [6.1 MEDIUM] Patches_squid3: upstream_squid3: needs-triage precise/esm_squid3: ignored (end of ESM support, was needs-triage) trusty_squid3: ignored (out of standard support) trusty/esm_squid3: DNE xenial_squid3: released (3.5.12-1ubuntu7.11) esm-infra/xenial_squid3: released (3.5.12-1ubuntu7.11) bionic_squid3: released (3.5.27-1ubuntu1.6) eoan_squid3: DNE focal_squid3: DNE groovy_squid3: DNE hirsute_squid3: DNE devel_squid3: DNE Patches_squid: upstream: https://github.com/squid-cache/squid/commit/5a90b4ce64c346ba7f317a278ba601091d9de076 upstream_squid: needs-triage precise/esm_squid: DNE trusty_squid: ignored (out of standard support) trusty/esm_squid: DNE xenial_squid: DNE bionic_squid: DNE eoan_squid: released (4.8-1ubuntu2.3) focal_squid: not-affected (4.10-1ubuntu1) groovy_squid: not-affected (4.10-1ubuntu1) hirsute_squid: not-affected (4.10-1ubuntu1) devel_squid: not-affected (4.10-1ubuntu1)