Details for this vulnerability have not been published by NIST at this point. Descriptions from software vendor advisories for this issue are provided below.
From VID-620685D6-0AA3-11EA-9673-4C72B94353B5:
Squid Team reports:
Problem Description: Due to incorrect data management Squid is
vulnerable to a information disclosure when processing HTTP Digest
Authentication.
Severity: Nonce tokens contain the raw byte value of a pointer which sits
within heap memory allocation. This information reduces ASLR protections
and may aid attackers isolating memory areas to target for remote code
execution attacks.
With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.
– Scott Cheney, Manager of Information Security, Sierra View Medical Center