CVE-2021-28651Missing Release of Memory after Effective Lifetime in Squid

Severity
7.5HIGHNVD
EPSS
6.2%
top 9.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 27
Latest updateJun 27

Description

An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a buffer-management bug, it allows a denial of service. When resolving a request with the urn: scheme, the parser leaks a small amount of memory. However, there is an unspecified attack methodology that can easily trigger a large amount of memory consumption.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

NVDsquid-cache/squid2.04.15+1
Debiansquid/squid< 4.13-10+3
Ubuntusquid/squid< 4.10-1ubuntu1.4

Also affects: Debian Linux 10.0, 9.0, Fedora 33, 34

Patches

🔴Vulnerability Details

4
OSV
squid3 vulnerabilities2024-06-27
OSV
squid, squid3 vulnerabilities2021-06-03
OSV
CVE-2021-28651: An issue was discovered in Squid before 42021-05-27
CVEList
CVE-2021-28651: An issue was discovered in Squid before 42021-05-27

📋Vendor Advisories

4
Ubuntu
Squid vulnerabilities2024-06-27
Ubuntu
Squid vulnerabilities2021-06-03
Red Hat
squid: denial of service in URN processing2021-05-10
Debian
CVE-2021-28651: squid - An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a buff...2021
CVE-2021-28651 — Squid-cache Squid vulnerability | cvebase