Back to search
CVE-2021-28116
Published: Mar 9, 2021
Modified: Aug 3, 2024
PUBLISHED
CVSS v3.1
3.7
LOW
Description
Squid through 4.14 and 5.x through 5.0.5, in some configurations, allows information disclosure because of an out-of-bounds read in WCCP protocol data. This can be leveraged as part of a chain for remote code execution as nobody.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AC:H/AV:N/A:N/C:L/I:N/PR:N/S:U/UI:N
Attack Complexity
High
Attack Vector
Network
Availability
None
Confidentiality
Low
Integrity
None
Privileges Required
None
Scope
Unchanged
User Interaction
None
References
http://www.squid-cache.org/Versions/
x_refsource_MISC
https://www.zerodayinitiative.com/advisories/ZDI-21-157/
x_refsource_MISC
GLSA-202105-14
vendor-advisory
x_refsource_GENTOO
FEDORA-2021-c0bec55ec7
vendor-advisory
x_refsource_FEDORA
FEDORA-2021-24af72ff2c
vendor-advisory
x_refsource_FEDORA
[oss-security] 20211004 CVE-2021-28116 / ZDI-CAN-11610 / SQUID-2020:12 Out-Of-Bounds memory access in WCCPv2
mailing-list
x_refsource_MLIST
DSA-5171
vendor-advisory
x_refsource_DEBIAN
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now