Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-46784

Опубликовано: 23 июн. 2022
Источник: redhat
CVSS3: 7.5

Описание

In Squid 3.x through 3.5.28, 4.x through 4.17, and 5.x before 5.6, due to improper buffer management, a Denial of Service can occur when processing long Gopher server responses.

A vulnerability was found in squid (Web proxy cache server). This issue occurs due to improper buffer management while processing Gopher server responses. This flaw leads to a remote denial of service or a crash if it receives specially crafted network traffic, either by mistake or a malicious actor.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6squidOut of support scope
Red Hat Enterprise Linux 6squid34Out of support scope
Red Hat Enterprise Linux 7squidFixedRHSA-2022:554211.07.2022
Red Hat Enterprise Linux 8squidFixedRHSA-2022:552607.07.2022
Red Hat Enterprise Linux 8.1 Update Services for SAP SolutionssquidFixedRHSA-2022:553007.07.2022
Red Hat Enterprise Linux 8.2 Extended Update SupportsquidFixedRHSA-2022:552907.07.2022
Red Hat Enterprise Linux 8.4 Extended Update SupportsquidFixedRHSA-2022:552807.07.2022
Red Hat Enterprise Linux 9squidFixedRHSA-2022:552707.07.2022

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-617
https://bugzilla.redhat.com/show_bug.cgi?id=2100721squid: DoS when processing gopher server responses

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 3 года назад

In Squid 3.x through 3.5.28, 4.x through 4.17, and 5.x before 5.6, due to improper buffer management, a Denial of Service can occur when processing long Gopher server responses.

CVSS3: 6.5
nvd
почти 3 года назад

In Squid 3.x through 3.5.28, 4.x through 4.17, and 5.x before 5.6, due to improper buffer management, a Denial of Service can occur when processing long Gopher server responses.

CVSS3: 6.5
debian
почти 3 года назад

In Squid 3.x through 3.5.28, 4.x through 4.17, and 5.x before 5.6, due ...

suse-cvrf
почти 3 года назад

Security update for squid

redos
почти 3 года назад

Уязвимость Squid

7.5 High

CVSS3

Уязвимость CVE-2021-46784