Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.146030
Category:Denial of Service
Title:Squid 2.0 < 4.14, 5.0.1 < 5.0.5 DoS Vulnerability (GHSA-ch36-9jhx-phm4, SQUID-2021:1)
Summary:Squid is prone to a denial of service (DoS) vulnerability in; the URN processing.
Description:Summary:
Squid is prone to a denial of service (DoS) vulnerability in
the URN processing.

Vulnerability Insight:
Due to a buffer management bug Squid is vulnerable to a DoS
attack against the server it is operating on.

This attack is limited to proxies which attempt to resolve a 'urn:' resource identifier. Support
for this resolving is enabled by default in all Squid.

This problem allows a malicious server in collaboration with a trusted client to consume
arbitrarily large amounts of memory on the server running Squid.

Lack of available memory resources impacts all services on the machine running Squid. Once
initiated the DoS situation will persist until Squid is shutdown.

This flaw was part of the 'Squid Caching Proxy Security Audit: 55 vulnerabilities and 35 0days'
publication in October 2023 and filed as 'RFC 2141 / 2169 (URN) Response Parsing Memory Leak'.

Affected Software/OS:
Squid version 2.0 through 4.14 and 5.0.1 through 5.0.5.

Solution:
Update to version 4.15, 5.0.6 or later. See the referenced vendor
advisory for a workaround.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2021-28651
Debian Security Information: DSA-4924 (Google Search)
https://www.debian.org/security/2021/dsa-4924
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T4EPIWUZDJAXADDHVOPKRBTQHPBR6H66/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LSQ3U54ZCNXR44QRPW3AV2VCS6K3TKCF/
http://seclists.org/fulldisclosure/2023/Oct/14
https://bugs.squid-cache.org/show_bug.cgi?id=5104
https://github.com/squid-cache/squid/security/advisories/GHSA-ch36-9jhx-phm4
https://lists.debian.org/debian-lts-announce/2021/06/msg00014.html
http://www.openwall.com/lists/oss-security/2023/10/11/3
CopyrightCopyright (C) 2021 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.