Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-28662

Опубликовано: 27 мая 2021
Источник: debian
EPSS Средний

Описание

An issue was discovered in Squid 4.x before 4.15 and 5.x before 5.0.6. If a remote server sends a certain response header over HTTP or HTTPS, there is a denial of service. This header can plausibly occur in benign network traffic.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
squidfixed4.13-10package

Примечания

  • https://github.com/squid-cache/squid/security/advisories/GHSA-jjq6-mh2h-g39h

  • http://www.squid-cache.org/Versions/v4/changesets/squid-4-b1c37c9e7b30d0efb5e5ccf8200f2a646b9c36f8.patch

  • https://megamansec.github.io/Squid-Security-Audit/vary-other-assert.html

EPSS

Процентиль: 94%
0.1363
Средний

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 4 лет назад

An issue was discovered in Squid 4.x before 4.15 and 5.x before 5.0.6. If a remote server sends a certain response header over HTTP or HTTPS, there is a denial of service. This header can plausibly occur in benign network traffic.

CVSS3: 6.5
redhat
около 4 лет назад

An issue was discovered in Squid 4.x before 4.15 and 5.x before 5.0.6. If a remote server sends a certain response header over HTTP or HTTPS, there is a denial of service. This header can plausibly occur in benign network traffic.

CVSS3: 6.5
nvd
около 4 лет назад

An issue was discovered in Squid 4.x before 4.15 and 5.x before 5.0.6. If a remote server sends a certain response header over HTTP or HTTPS, there is a denial of service. This header can plausibly occur in benign network traffic.

CVSS3: 7.4
fstec
около 4 лет назад

Уязвимость прокси-сервера Squid, существующая из-за недостаточной проверки ввода при обработке ответов HTTP, позволяющая нарушителю вызвать отказ в обслуживании

suse-cvrf
около 4 лет назад

Security update for squid

EPSS

Процентиль: 94%
0.1363
Средний