ALT-PU-2021-2058-1
Closed vulnerabilities
BDU:2021-01823
Уязвимость реализации конфигурации uri_whitespace прокси-сервера Squid, позволяющая нарушителю отправить скрытый HTTP-запрос (атака типа HTTP Request Smuggling)
BDU:2021-02728
Уязвимость прокси-сервера Squid, существующая из-за недостаточной проверки введенных пользователем данных при доставке ответов на запросы диапазона HTTP, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2021-02729
Уязвимость прокси-сервера Squid, существующая из-за недостаточной проверки введенных пользователем данных при выполнении запросов диапазона HTTP, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2021-02730
Уязвимость компонента Cache Manager API прокси-сервера Squid, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2021-02731
Уязвимость прокси-сервера Squid, существующая из-за недостаточной проверки ввода при обработке ответов HTTP, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2021-02732
Уязвимость прокси-сервера Squid, существующая из-за недостаточной проверки ввода при разрешении идентификаторов ресурсов «urn:», позволяющая нарушителю вызвать отказ в обслуживании
BDU:2021-05158
Уязвимость прокси-сервера Squid, связанная с целочисленным переполнением, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2021-05301
Уязвимость прокси-сервера Squid, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2021-06197
Уязвимость прокси-сервера Squid, связанная с чтением за границами буфера, позволяющая нарушителю получить доступ к конфиденциальной информации
Modified: 2024-11-21
CVE-2020-25097
An issue was discovered in Squid through 4.13 and 5.x through 5.0.4. Due to improper input validation, it allows a trusted client to perform HTTP Request Smuggling and access services otherwise forbidden by the security controls. This occurs for certain uri_whitespace configuration settings.
- http://www.squid-cache.org/Versions/v4/changesets/SQUID-2020_11.patch
- http://www.squid-cache.org/Versions/v4/changesets/SQUID-2020_11.patch
- http://www.squid-cache.org/Versions/v5/changesets/SQUID-2020_11.patch
- http://www.squid-cache.org/Versions/v5/changesets/SQUID-2020_11.patch
- https://github.com/squid-cache/squid/security/advisories/GHSA-jvf6-h9gj-pmj6
- https://github.com/squid-cache/squid/security/advisories/GHSA-jvf6-h9gj-pmj6
- FEDORA-2021-ecb24e0b9d
- FEDORA-2021-ecb24e0b9d
- FEDORA-2021-7d86bec29e
- FEDORA-2021-7d86bec29e
- FEDORA-2021-76f09062a7
- FEDORA-2021-76f09062a7
- GLSA-202105-14
- GLSA-202105-14
- https://security.netapp.com/advisory/ntap-20210727-0010/
- https://security.netapp.com/advisory/ntap-20210727-0010/
- DSA-4873
- DSA-4873
Modified: 2024-11-21
CVE-2021-28116
Squid through 4.14 and 5.x through 5.0.5, in some configurations, allows information disclosure because of an out-of-bounds read in WCCP protocol data. This can be leveraged as part of a chain for remote code execution as nobody.
- [oss-security] 20211004 CVE-2021-28116 / ZDI-CAN-11610 / SQUID-2020:12 Out-Of-Bounds memory access in WCCPv2
- [oss-security] 20211004 CVE-2021-28116 / ZDI-CAN-11610 / SQUID-2020:12 Out-Of-Bounds memory access in WCCPv2
- http://www.squid-cache.org/Versions/
- http://www.squid-cache.org/Versions/
- https://github.com/squid-cache/squid/security/advisories/GHSA-rgf3-9v3p-qp82
- https://github.com/squid-cache/squid/security/advisories/GHSA-rgf3-9v3p-qp82
- FEDORA-2021-c0bec55ec7
- FEDORA-2021-c0bec55ec7
- FEDORA-2021-24af72ff2c
- FEDORA-2021-24af72ff2c
- GLSA-202105-14
- GLSA-202105-14
- DSA-5171
- DSA-5171
- https://www.zerodayinitiative.com/advisories/ZDI-21-157/
- https://www.zerodayinitiative.com/advisories/ZDI-21-157/
Modified: 2024-11-21
CVE-2021-28651
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a buffer-management bug, it allows a denial of service. When resolving a request with the urn: scheme, the parser leaks a small amount of memory. However, there is an unspecified attack methodology that can easily trigger a large amount of memory consumption.
- 20231016 Squid Caching Proxy Security Audit: 55 Vulnerabilities, 35 0days.
- 20231016 Squid Caching Proxy Security Audit: 55 Vulnerabilities, 35 0days.
- [oss-security] 20231011 Squid Caching Proxy Security Audit: 55 Vulnerabilities, 35 0days.
- [oss-security] 20231011 Squid Caching Proxy Security Audit: 55 Vulnerabilities, 35 0days.
- https://bugs.squid-cache.org/show_bug.cgi?id=5104
- https://bugs.squid-cache.org/show_bug.cgi?id=5104
- https://github.com/squid-cache/squid/security/advisories/GHSA-ch36-9jhx-phm4
- https://github.com/squid-cache/squid/security/advisories/GHSA-ch36-9jhx-phm4
- [debian-lts-announce] 20210614 [SECURITY] [DLA 2685-1] squid3 security update
- [debian-lts-announce] 20210614 [SECURITY] [DLA 2685-1] squid3 security update
- FEDORA-2021-c0bec55ec7
- FEDORA-2021-c0bec55ec7
- FEDORA-2021-24af72ff2c
- FEDORA-2021-24af72ff2c
- https://security.netapp.com/advisory/ntap-20210716-0007/
- https://security.netapp.com/advisory/ntap-20210716-0007/
- DSA-4924
- DSA-4924
Modified: 2024-11-21
CVE-2021-28652
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to incorrect parser validation, it allows a Denial of Service attack against the Cache Manager API. This allows a trusted client to trigger memory leaks that. over time, lead to a Denial of Service via an unspecified short query string. This attack is limited to clients with Cache Manager API access privilege.
- 20231016 Squid Caching Proxy Security Audit: 55 Vulnerabilities, 35 0days.
- 20231016 Squid Caching Proxy Security Audit: 55 Vulnerabilities, 35 0days.
- [oss-security] 20231011 Squid Caching Proxy Security Audit: 55 Vulnerabilities, 35 0days.
- [oss-security] 20231011 Squid Caching Proxy Security Audit: 55 Vulnerabilities, 35 0days.
- https://bugs.squid-cache.org/show_bug.cgi?id=5106
- https://bugs.squid-cache.org/show_bug.cgi?id=5106
- https://github.com/squid-cache/squid/security/advisories/GHSA-m47m-9hvw-7447
- https://github.com/squid-cache/squid/security/advisories/GHSA-m47m-9hvw-7447
- [debian-lts-announce] 20210614 [SECURITY] [DLA 2685-1] squid3 security update
- [debian-lts-announce] 20210614 [SECURITY] [DLA 2685-1] squid3 security update
- FEDORA-2021-c0bec55ec7
- FEDORA-2021-c0bec55ec7
- FEDORA-2021-24af72ff2c
- FEDORA-2021-24af72ff2c
- DSA-4924
- DSA-4924
Modified: 2024-11-21
CVE-2021-28662
An issue was discovered in Squid 4.x before 4.15 and 5.x before 5.0.6. If a remote server sends a certain response header over HTTP or HTTPS, there is a denial of service. This header can plausibly occur in benign network traffic.
- 20231016 Squid Caching Proxy Security Audit: 55 Vulnerabilities, 35 0days.
- 20231016 Squid Caching Proxy Security Audit: 55 Vulnerabilities, 35 0days.
- [oss-security] 20231011 Squid Caching Proxy Security Audit: 55 Vulnerabilities, 35 0days.
- [oss-security] 20231011 Squid Caching Proxy Security Audit: 55 Vulnerabilities, 35 0days.
- http://www.squid-cache.org/Versions/v6/changesets/squid-6-051824924c709bd6162a378f746fb859454c674e.patch
- http://www.squid-cache.org/Versions/v6/changesets/squid-6-051824924c709bd6162a378f746fb859454c674e.patch
- https://github.com/squid-cache/squid/commit/051824924c709bd6162a378f746fb859454c674e
- https://github.com/squid-cache/squid/commit/051824924c709bd6162a378f746fb859454c674e
- https://github.com/squid-cache/squid/security/advisories/GHSA-jjq6-mh2h-g39h
- https://github.com/squid-cache/squid/security/advisories/GHSA-jjq6-mh2h-g39h
- FEDORA-2021-c0bec55ec7
- FEDORA-2021-c0bec55ec7
- FEDORA-2021-24af72ff2c
- FEDORA-2021-24af72ff2c
- DSA-4924
- DSA-4924
Modified: 2024-11-21
CVE-2021-31806
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a memory-management bug, it is vulnerable to a Denial of Service attack (against all clients using the proxy) via HTTP Range request processing.
- 20231016 Squid Caching Proxy Security Audit: 55 Vulnerabilities, 35 0days.
- 20231016 Squid Caching Proxy Security Audit: 55 Vulnerabilities, 35 0days.
- [oss-security] 20231011 Squid Caching Proxy Security Audit: 55 Vulnerabilities, 35 0days.
- [oss-security] 20231011 Squid Caching Proxy Security Audit: 55 Vulnerabilities, 35 0days.
- http://www.squid-cache.org/Versions/v4/changesets/squid-4-e7cf864f938f24eea8af0692c04d16790983c823.patch
- http://www.squid-cache.org/Versions/v4/changesets/squid-4-e7cf864f938f24eea8af0692c04d16790983c823.patch
- https://github.com/squid-cache/squid/security/advisories/GHSA-pxwq-f3qr-w2xf
- https://github.com/squid-cache/squid/security/advisories/GHSA-pxwq-f3qr-w2xf
- [debian-lts-announce] 20210614 [SECURITY] [DLA 2685-1] squid3 security update
- [debian-lts-announce] 20210614 [SECURITY] [DLA 2685-1] squid3 security update
- FEDORA-2021-c0bec55ec7
- FEDORA-2021-c0bec55ec7
- FEDORA-2021-24af72ff2c
- FEDORA-2021-24af72ff2c
- https://security.netapp.com/advisory/ntap-20210716-0007/
- https://security.netapp.com/advisory/ntap-20210716-0007/
- DSA-4924
- DSA-4924
Modified: 2024-11-21
CVE-2021-31807
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. An integer overflow problem allows a remote server to achieve Denial of Service when delivering responses to HTTP Range requests. The issue trigger is a header that can be expected to exist in HTTP traffic without any malicious intent.
- 20231016 Squid Caching Proxy Security Audit: 55 Vulnerabilities, 35 0days.
- 20231016 Squid Caching Proxy Security Audit: 55 Vulnerabilities, 35 0days.
- [oss-security] 20231011 Squid Caching Proxy Security Audit: 55 Vulnerabilities, 35 0days.
- [oss-security] 20231011 Squid Caching Proxy Security Audit: 55 Vulnerabilities, 35 0days.
- http://www.squid-cache.org/Versions/v4/changesets/squid-4-e7cf864f938f24eea8af0692c04d16790983c823.patch
- http://www.squid-cache.org/Versions/v4/changesets/squid-4-e7cf864f938f24eea8af0692c04d16790983c823.patch
- https://github.com/squid-cache/squid/security/advisories/GHSA-pxwq-f3qr-w2xf
- https://github.com/squid-cache/squid/security/advisories/GHSA-pxwq-f3qr-w2xf
- [debian-lts-announce] 20210614 [SECURITY] [DLA 2685-1] squid3 security update
- [debian-lts-announce] 20210614 [SECURITY] [DLA 2685-1] squid3 security update
- FEDORA-2021-c0bec55ec7
- FEDORA-2021-c0bec55ec7
- FEDORA-2021-24af72ff2c
- FEDORA-2021-24af72ff2c
- https://security.netapp.com/advisory/ntap-20210716-0007/
- https://security.netapp.com/advisory/ntap-20210716-0007/
Modified: 2024-11-21
CVE-2021-31808
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to an input-validation bug, it is vulnerable to a Denial of Service attack (against all clients using the proxy). A client sends an HTTP Range request to trigger this.
- 20231016 Squid Caching Proxy Security Audit: 55 Vulnerabilities, 35 0days.
- 20231016 Squid Caching Proxy Security Audit: 55 Vulnerabilities, 35 0days.
- [oss-security] 20231011 Squid Caching Proxy Security Audit: 55 Vulnerabilities, 35 0days.
- [oss-security] 20231011 Squid Caching Proxy Security Audit: 55 Vulnerabilities, 35 0days.
- http://www.squid-cache.org/Versions/v4/changesets/squid-4-e7cf864f938f24eea8af0692c04d16790983c823.patch
- http://www.squid-cache.org/Versions/v4/changesets/squid-4-e7cf864f938f24eea8af0692c04d16790983c823.patch
- https://github.com/squid-cache/squid/security/advisories/GHSA-pxwq-f3qr-w2xf
- https://github.com/squid-cache/squid/security/advisories/GHSA-pxwq-f3qr-w2xf
- [debian-lts-announce] 20210614 [SECURITY] [DLA 2685-1] squid3 security update
- [debian-lts-announce] 20210614 [SECURITY] [DLA 2685-1] squid3 security update
- FEDORA-2021-c0bec55ec7
- FEDORA-2021-c0bec55ec7
- FEDORA-2021-24af72ff2c
- FEDORA-2021-24af72ff2c
- https://security.netapp.com/advisory/ntap-20210716-0007/
- https://security.netapp.com/advisory/ntap-20210716-0007/
- DSA-4924
- DSA-4924
Modified: 2024-11-21
CVE-2021-33620
Squid before 4.15 and 5.x before 5.0.6 allows remote servers to cause a denial of service (affecting availability to all clients) via an HTTP response. The issue trigger is a header that can be expected to exist in HTTP traffic without any malicious intent by the server.
- 20231016 Squid Caching Proxy Security Audit: 55 Vulnerabilities, 35 0days.
- 20231016 Squid Caching Proxy Security Audit: 55 Vulnerabilities, 35 0days.
- [oss-security] 20231011 Squid Caching Proxy Security Audit: 55 Vulnerabilities, 35 0days.
- [oss-security] 20231011 Squid Caching Proxy Security Audit: 55 Vulnerabilities, 35 0days.
- http://www.squid-cache.org/Versions/v4/changesets/squid-4-1e05a85bd28c22c9ca5d3ac9f5e86d6269ec0a8c.patch
- http://www.squid-cache.org/Versions/v4/changesets/squid-4-1e05a85bd28c22c9ca5d3ac9f5e86d6269ec0a8c.patch
- http://www.squid-cache.org/Versions/v5/changesets/squid-5-8af775ed98bfd610f9ce762fe177e01b2675588c.patch
- http://www.squid-cache.org/Versions/v5/changesets/squid-5-8af775ed98bfd610f9ce762fe177e01b2675588c.patch
- https://github.com/squid-cache/squid/security/advisories/GHSA-572g-rvwr-6c7f
- https://github.com/squid-cache/squid/security/advisories/GHSA-572g-rvwr-6c7f
- [debian-lts-announce] 20210614 [SECURITY] [DLA 2685-1] squid3 security update
- [debian-lts-announce] 20210614 [SECURITY] [DLA 2685-1] squid3 security update
- FEDORA-2021-c0bec55ec7
- FEDORA-2021-c0bec55ec7
- FEDORA-2021-24af72ff2c
- FEDORA-2021-24af72ff2c