CVE-2021-46784Reachable Assertion in Squid

Severity
6.5MEDIUMNVD
EPSS
12.7%
top 5.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 17

Description

In Squid 3.x through 3.5.28, 4.x through 4.17, and 5.x before 5.6, due to improper buffer management, a Denial of Service can occur when processing long Gopher server responses.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

NVDsquid-cache/squid5.05.6+2
Debiansquid/squid< 4.13-10+deb11u1+3

Also affects: Debian Linux 10.0, 11.0, 12.0

Patches

🔴Vulnerability Details

2
OSV
CVE-2021-46784: In Squid 32022-07-17
CVEList
CVE-2021-46784: In Squid 32022-07-17

📋Vendor Advisories

3
Red Hat
squid: DoS when processing gopher server responses2022-06-23
Ubuntu
Squid vulnerability2022-06-22
Debian
CVE-2021-46784: squid - In Squid 3.x through 3.5.28, 4.x through 4.17, and 5.x before 5.6, due to improp...2021
CVE-2021-46784 — Reachable Assertion in Squid | cvebase