{"id":"CVE-2019-12522","details":"An issue was discovered in Squid through 4.7. When Squid is run as root, it spawns its child processes as a lesser user, by default the user nobody. This is done via the leave_suid call. leave_suid leaves the Saved UID as 0. This makes it trivial for an attacker who has compromised the child process to escalate their privileges back to root.","modified":"2026-07-08T16:07:43.670830Z","published":"2020-04-15T19:15:12.473Z","references":[{"type":"ADVISORY","url":"https://gitlab.com/jeriko.one/security/-/blob/master/squid/CVEs/CVE-2019-12522.txt"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20210205-0006/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/squid-cache/squid","events":[{"introduced":"0"},{"last_affected":"2e17b02616d37206ba9cccc53c20667624fbef9f"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:squid-cache:squid:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"4.7"}]}}],"versions":["SQUID_4_7","SQUID_4_6","SQUID_4_5","SQUID_4_4","SQUID_4_3","SQUID_4_2","SQUID_4_1","SQUID_4_0_25","SQUID_4_0_24","SQUID_4_0_23","SQUID_4_0_22","SQUID_4_0_21","SQUID_4_0_20","SQUID_4_0_19","SQUID_4_0_18","SQUID_4_0_17","SQUID_4_0_16","SQUID_4_0_15","SQUID_4_0_14","SQUID_4_0_13","SQUID_4_0_12","SQUID_4_0_11","SQUID_4_0_10","SQUID_4_0_9","SQUID_4_0_8","SQUID_4_0_7","SQUID_4_0_6","SQUID_4_0_5","SQUID_4_0_4","SQUID_4_0_3","SQUID_4_0_2","SQUID_4_0_1","take00","SQUID_3_0_RC1","SQUID_3_0_PRE7","SQUID_3_0_PRE6","SQUID_3_0_PRE5","SQUID_3_0_PRE4","SQUID_3_0_PRE3","SQUID_3_0_PRE2","SQUID_3_0_PRE1","HISTORIC_RELEASES"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-12522.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L"}]}