Due to incorrect string termination, Squid cachemgr.cgi 4.0 through 4.7 may access unallocated memory. On systems with memory access protections, this can cause the CGI process to terminate unexpectedly, resulting in a denial of service for all clients using it.
https://www.debian.org/security/2019/dsa-4507
https://usn.ubuntu.com/4213-1/
https://seclists.org/bugtraq/2019/Aug/42
https://bugs.squid-cache.org/show_bug.cgi?id=4937
http://www.squid-cache.org/Advisories/SQUID-2019_1.txt
http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00056.html
http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00053.html