CVE-2021-28652

Name
CVE-2021-28652
Description
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to incorrect parser validation, it allows a Denial of Service attack against the Cache Manager API. This allows a trusted client to trigger memory leaks that. over time, lead to a Denial of Service via an unspecified short query string. This attack is limited to clients with Cache Manager API access privilege.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://github.com/squid-cache/squid/security/advisories/GHSA-m47m-9hvw-7447
MISC https://bugs.squid-cache.org/show_bug.cgi?id=5106
DEBIAN https://www.debian.org/security/2021/dsa-4924
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T4EPIWUZDJAXADDHVOPKRBTQHPBR6H66/
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LSQ3U54ZCNXR44QRPW3AV2VCS6K3TKCF/
MLIST https://lists.debian.org/debian-lts-announce/2021/06/msg00014.html

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:squid-cache:squid:*:*:*:*:*:*:*:* squid >= 1.0 < 4.15
cpe:2.3:a:squid-cache:squid:*:*:*:*:*:*:*:* squid >= 5.0 < 5.0.6

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
squid 3.10-main 4.15-r0 Natanael Copa <ncopa@alpinelinux.org> fixed