CVE-2021-28651: Input Validation
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a buffer-management bug, it allows a denial of service. When resolving a request with the urn: scheme, the parser leaks a small amount of memory. However, there is an unspecified attack methodology that can easily trigger a large amount of memory consumption.
Other sources
Due to an input validation bug Squid is vulnerable to a Denial of Service against all clients using the proxy. This problem allows a malicious server in collaboration with a trusted client to consume arbitrarily large amounts of memory on the server running Squid. Lack of available memory resources impacts all services on the machine running Squid. Once initiated the DoS situation will persist until Squid is shutdown.
Upstream security advisory: https://github.com/squid-cache/squid/security/advisories/GHSA-ch36-9jhx-phm4
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-28651?
CVE-2021-28651 is a vulnerability in Squid before 4.15 and 5.x before 5.0.6 that allows a denial of service.
How does CVE-2021-28651 impact Squid?
CVE-2021-28651 allows an attacker to trigger a denial of service condition in Squid.
What is the severity of CVE-2021-28651?
CVE-2021-28651 has a severity rating of high (7.5).
Are there any known attack methodologies for CVE-2021-28651?
Yes, there is an unspecified attack methodology that can easily trigger the vulnerability.
How can I fix CVE-2021-28651?
To fix CVE-2021-28651, you should update Squid to version 4.15 or 5.0.6 or later, as recommended by the vendor.