First published: Thu Jun 03 2021(Updated: )
Joshua Rogers discovered that Squid incorrectly handled requests with the urn: scheme. A remote attacker could possibly use this issue to cause Squid to consume resources, leading to a denial of service. (CVE-2021-28651) Joshua Rogers discovered that Squid incorrectly handled requests to the Cache Manager API. A remote attacker with access privileges could possibly use this issue to cause Squid to consume resources, leading to a denial of service. This issue was only addressed in Ubuntu 20.04 LTS, Ubuntu 20.10, and Ubuntu 21.04. (CVE-2021-28652) Joshua Rogers discovered that Squid incorrectly handled certain response headers. A remote attacker could possibly use this issue to cause Squid to crash, resulting in a denial of service. This issue was only affected Ubuntu 20.04 LTS, Ubuntu 20.10, and Ubuntu 21.04. (CVE-2021-28662) Joshua Rogers discovered that Squid incorrectly handled range request processing. A remote attacker could possibly use this issue to cause Squid to crash, resulting in a denial of service. (CVE-2021-31806, CVE-2021-31807, CVE-2021-31808) Joshua Rogers discovered that Squid incorrectly handled certain HTTP responses. A remote attacker could possibly use this issue to cause Squid to crash, resulting in a denial of service. (CVE-2021-33620)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/squid | <4.13-1ubuntu4.1 | 4.13-1ubuntu4.1 |
Ubuntu | =21.04 | |
All of | ||
ubuntu/squid | <4.13-1ubuntu2.2 | 4.13-1ubuntu2.2 |
Ubuntu | =20.10 | |
All of | ||
ubuntu/squid | <4.10-1ubuntu1.4 | 4.10-1ubuntu1.4 |
Ubuntu | =20.04 | |
All of | ||
ubuntu/squid | <3.5.27-1ubuntu1.11 | 3.5.27-1ubuntu1.11 |
Ubuntu | =18.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
The severity of USN-4981-1 is considered high due to the potential for denial of service caused by resource consumption.
To fix USN-4981-1, upgrade Squid to the corrected versions provided in the advisory.
USN-4981-1 affects various versions of Squid on specific Ubuntu releases including 21.04, 20.10, 20.04, and 18.04.
The vulnerability in USN-4981-1 was discovered by Joshua Rogers.
USN-4981-1 relates to a remote denial of service attack that exploits improper handling of requests with the urn: scheme.