UBUNTU-CVE-2021-28116
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-28116
UBUNTU-CVE-2021-28116
Summary:
Details: Squid through 4.14 and 5.x through 5.0.5, in some configurations, allows information disclosure because of an out-of-bounds read in WCCP protocol data. This can be leveraged as part of a chain for remote code execution as nobody.
References: https://ubuntu.com/security/CVE-2021-28116, https://www.zerodayinitiative.com/advisories/ZDI-21-157/, http://www.squid-cache.org/Versions/, https://github.com/squid-cache/squid/security/advisories/GHSA-rgf3-9v3p-qp82, https://www.openwall.com/lists/oss-security/2021/10/04/1, https://ubuntu.com/security/notices/USN-5104-1, https://www.cve.org/CVERecord?id=CVE-2021-28116
Affected packages
Package
Name: squid3
Purl: pkg:deb/ubuntu/[email protected]+esm6?arch=source&distro=esm-infra/xenial
Affected ranges
Type: ECOSYSTEM
Events:
