V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2021-28651
AST
High

An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a buffer-management bug, it allows a denial of service. When reso…

CVSS
7.4
High
EPSS
0.07
p93
Published
2021-01-01
Updated
2021-01-01
Description

An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a buffer-management bug, it allows a denial of service. When resolving a request with the urn: scheme, the parser leaks a small amount of memory. However, there is an unspecified attack methodology that can easily trigger a large amount of memory consumption.

Tags · CWE
Pre-auth
CWE-401
Affected products
SquidSquidSquidSquidSquidSquidSquidSquidSquidSquidSquidSquidSquidSquidSquid3Squid3Squid3Squid3Squid3Squid3
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H
Timeline
2021-01-01
Published
2021-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: R
Required (R)
Scope
S: C
Changed (C)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: N
None (N)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.074 · p93
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
squidTracked
squidTracked
squidTracked
squidTracked
squidTracked
squidTracked
squidTracked
squidTracked
squidTracked
squidTracked
squidTracked
squidTracked
squidTracked
squidTracked
squid3Tracked
squid3Tracked
squid3Tracked
squid3Tracked
squid3Tracked
squid3Tracked
Showing first 20 of 24
Source databases
AST
DEB
CVE
RED
UBU
Related vulnerabilities