UBUNTU-CVE-2021-28651
Dashboard / Vulnerabilities / UBUNTU-CVE-2021-28651
UBUNTU-CVE-2021-28651
Summary:
Details: An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a buffer-management bug, it allows a denial of service. When resolving a request with the urn: scheme, the parser leaks a small amount of memory. However, there is an unspecified attack methodology that can easily trigger a large amount of memory consumption.
References: https://ubuntu.com/security/CVE-2021-28651, https://github.com/squid-cache/squid/security/advisories/GHSA-ch36-9jhx-phm4, https://ubuntu.com/security/notices/USN-4981-1, https://www.cve.org/CVERecord?id=CVE-2021-28651, https://ubuntu.com/security/notices/USN-6857-1
Affected packages
Package
Name: squid3
Purl: pkg:deb/ubuntu/[email protected]+esm3?arch=source&distro=esm-infra/xenial
Affected ranges
Type: ECOSYSTEM
Events:
