CVE-2021-28651
27.05.2021, 12:15
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a buffer-management bug, it allows a denial of service. When resolving a request with the urn: scheme, the parser leaks a small amount of memory. However, there is an unspecified attack methodology that can easily trigger a large amount of memory consumption.Enginsight
Vendor | Product | Version |
---|---|---|
squid-cache | squid | 2.0 ≤ 𝑥 < 4.15 |
squid-cache | squid | 5.0 ≤ 𝑥 < 5.0.6 |
debian | debian_linux | 9.0 |
debian | debian_linux | 10.0 |
netapp | cloud_manager | - |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
squid |
| ||||||||||||||||||||||||
squid3 |
|
Common Weakness Enumeration
References