USN-4981-1: Squid vulnerabilities
Joshua Rogers discovered that Squid incorrectly handled requests with the urn: scheme. A remote attacker could possibly use this issue to cause Squid to consume resources, leading to a denial of service. (CVE-2021-28651) Joshua Rogers discovered that Squid incorrectly handled requests to the Cache Manager API. A remote attacker with access privileges could possibly use this issue to cause Squid to consume resources, leading to a denial of service. This issue was only addressed in Ubuntu 20.04 LTS, Ubuntu 20.10, and Ubuntu 21.04. (CVE-2021-28652) Joshua Rogers discovered that Squid incorrectly handled certain response headers. A remote attacker could possibly use this issue to cause Squid to crash, resulting in a denial of service. This issue was only affected Ubuntu 20.04 LTS, Ubuntu 20.10, and Ubuntu 21.04. (CVE-2021-28662) Joshua Rogers discovered that Squid incorrectly handled range request processing. A remote attacker could possibly use this issue to cause Squid to crash, resulting in a denial of service. (CVE-2021-31806, CVE-2021-31807, CVE-2021-31808) Joshua Rogers discovered that Squid incorrectly handled certain HTTP responses. A remote attacker could possibly use this issue to cause Squid to crash, resulting in a denial of service. (CVE-2021-33620)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-4981-1?
The severity of USN-4981-1 is considered high due to the potential for denial of service caused by resource consumption.
How do I fix USN-4981-1?
To fix USN-4981-1, upgrade Squid to the corrected versions provided in the advisory.
What software is affected by USN-4981-1?
USN-4981-1 affects various versions of Squid on specific Ubuntu releases including 21.04, 20.10, 20.04, and 18.04.
Who discovered the vulnerability in USN-4981-1?
The vulnerability in USN-4981-1 was discovered by Joshua Rogers.
What type of attack does USN-4981-1 relate to?
USN-4981-1 relates to a remote denial of service attack that exploits improper handling of requests with the urn: scheme.