Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-28116

Опубликовано: 09 фев. 2021
Источник: redhat
CVSS3: 5.3
EPSS Средний

Описание

Squid through 4.14 and 5.x through 5.0.5, in some configurations, allows information disclosure because of an out-of-bounds read in WCCP protocol data. This can be leveraged as part of a chain for remote code execution as nobody.

A flaw was found in squid. An out-of-bounds read in the WCCP protocol can be leveraged as part of a chain for remote code execution leading to an information disclosure. The highest threat from this vulnerability is to data confidentiality.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6squidOut of support scope
Red Hat Enterprise Linux 6squid34Out of support scope
Red Hat Enterprise Linux 7squidOut of support scope
Red Hat Enterprise Linux 9squidNot affected
Red Hat Enterprise Linux 8squidFixedRHSA-2022:193910.05.2022

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125->CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1939939squid: out-of-bounds read in WCCP protocol data may lead to information disclosure

EPSS

Процентиль: 93%
0.10515
Средний

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 3.7
ubuntu
больше 4 лет назад

Squid through 4.14 and 5.x through 5.0.5, in some configurations, allows information disclosure because of an out-of-bounds read in WCCP protocol data. This can be leveraged as part of a chain for remote code execution as nobody.

CVSS3: 3.7
nvd
больше 4 лет назад

Squid through 4.14 and 5.x through 5.0.5, in some configurations, allows information disclosure because of an out-of-bounds read in WCCP protocol data. This can be leveraged as part of a chain for remote code execution as nobody.

CVSS3: 3.7
debian
больше 4 лет назад

Squid through 4.14 and 5.x through 5.0.5, in some configurations, allo ...

suse-cvrf
почти 4 года назад

Security update for squid

suse-cvrf
почти 4 года назад

Security update for squid

EPSS

Процентиль: 93%
0.10515
Средний

5.3 Medium

CVSS3