CVE-2021-28116

Related Vulnerabilities: CVE-2021-28116  

Squid through 4.14 and 5.x through 5.0.5, in some configurations, allows information disclosure because of an out-of-bounds read in WCCP protocol data. This can be leveraged as part of a chain for remote code execution as nobody.

Description

The MITRE CVE dictionary describes this issue as:

Squid through 4.14 and 5.x through 5.0.5, in some configurations, allows information disclosure because of an out-of-bounds read in WCCP protocol data. This can be leveraged as part of a chain for remote code execution as nobody.

Additional Information

  • Bugzilla 1939939: CVE-2021-28116 squid: an out-of-bounds read in WCCP protocol data may lead to information disclosure
  • CWE-125: Out-of-bounds Read
  • FAQ: Frequently asked questions about CVE-2021-28116