CVE-2021-28116
09.03.2021, 22:15
Squid through 4.14 and 5.x through 5.0.5, in some configurations, allows information disclosure because of an out-of-bounds read in WCCP protocol data. This can be leveraged as part of a chain for remote code execution as nobody.Enginsight
| Vendor | Product | Version |
|---|---|---|
| squid-cache | squid | 𝑥 ≤ 4.14 |
| squid-cache | squid | 5.0 ≤ 𝑥 ≤ 5.0.5 |
| debian | debian_linux | 10.0 |
| debian | debian_linux | 11.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| squid |
| ||||||||||||||||||||||||
| squid3 |
|
Common Weakness Enumeration
References