5
CVSSv2

CVE-2021-28651

Published: 27/05/2021 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

An issue exists in Squid prior to 4.15 and 5.x prior to 5.0.6. Due to a buffer-management bug, it allows a denial of service. When resolving a request with the urn: scheme, the parser leaks a small amount of memory. However, there is an unspecified attack methodology that can easily trigger a large amount of memory consumption.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

squid-cache squid

debian debian linux 9.0

debian debian linux 10.0

fedoraproject fedora 33

fedoraproject fedora 34

netapp cloud manager -

Vendor Advisories

Debian Bug report logs - #988893 squid: CVE-2021-28651 Package: src:squid; Maintainer for src:squid is Luigi Gangitano <luigi@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 20 May 2021 19:27:01 UTC Severity: grave Tags: security, upstream Found in versions squid/413-9, squid/46-1, sq ...
Multiple denial of service vulnerabilities were discovered in the Squid proxy caching server For the stable distribution (buster), these problems have been fixed in version 46-1+deb10u6 We recommend that you upgrade your squid packages For the detailed security status of squid please refer to its security tracker page at: security-track ...
An issue was discovered in Squid before 415 and 5x before 506 Due to a buffer-management bug, it allows a denial of service When resolving a request with the urn: scheme, the parser leaks a small amount of memory However, there is an unspecified attack methodology that can easily trigger a large amount of memory consumption (CVE-2021-28651) ...
An issue was discovered in Squid before 415 and 5x before 506 Due to a buffer-management bug, it allows a denial of service When resolving a request with the urn: scheme, the parser leaks a small amount of memory However, there is an unspecified attack methodology that can easily trigger a large amount of memory consumption (CVE-2021-28651) ...
Squid through 414 and 5x through 505, in some configurations, allows information disclosure because of an out-of-bounds read in WCCP protocol data This can be leveraged as part of a chain for remote code execution as nobody (CVE-2021-28116) An issue was discovered in Squid before 415 and 5x before 506 Due to a buffer-management bug, it a ...
An input validation flaw was found in Squid This issue could allow a malicious server in collaboration with a trusted client to consume arbitrarily large amounts of memory on the server running Squid The highest threat from this vulnerability is to system availability ...
Severity Unknown Remote Unknown Type Unknown Description AVG-1949 squid 414-1 Unknown Vulnerable ...