CVE-2021-46784: Medium severity Squid-Cache Squid vulnerability
Published Jul 17, 2022
·Updated
In Squid 3.x through 3.5.28, 4.x through 4.17, and 5.x before 5.6, due to improper buffer management, a Denial of Service can occur when processing long Gopher server responses.
Affected Software
7 affected componentsFixes available
Squid-Cache Squid>=3.0<=3.5.28
Squid-Cache Squid>=4.0<=4.17
Squid-Cache Squid>=5.0<5.6
Debian Debian Linux=10.0
Debian Debian Linux=11.0
Debian Debian Linux=12.0
debian/squid
4.13-10+deb11u34.13-10+deb11u65.7-2+deb12u55.7-2+deb12u46.13-2+deb13u17.4-1
Remediation
Event History
Jul 17, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Feb 24, 2026
Data Sourced
via Debian·10:47 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this Squid vulnerability?
The vulnerability ID is CVE-2021-46784.
2
What is the severity level of CVE-2021-46784?
The severity level of CVE-2021-46784 is medium (6.5).
3
What is affected by CVE-2021-46784?
Squid versions 3.x through 3.5.28, 4.x through 4.17, and 5.x before 5.6 are affected by CVE-2021-46784.
4
What is the impact of CVE-2021-46784?
CVE-2021-46784 can cause a Denial of Service (DoS) when processing long Gopher server responses.
5
How can I fix CVE-2021-46784?
To fix CVE-2021-46784, it is recommended to update to Squid versions 4.6-1+deb10u7, 4.6-1+deb10u8, 4.13-10+deb11u2, or 5.7-2 (or later).