![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.146030 |
Category: | Denial of Service |
Title: | Squid 2.0 < 4.14, 5.0.1 < 5.0.5 DoS Vulnerability (GHSA-ch36-9jhx-phm4, SQUID-2021:1) |
Summary: | Squid is prone to a denial of service (DoS) vulnerability in; the URN processing. |
Description: | Summary: Squid is prone to a denial of service (DoS) vulnerability in the URN processing. Vulnerability Insight: Due to a buffer management bug Squid is vulnerable to a DoS attack against the server it is operating on. This attack is limited to proxies which attempt to resolve a 'urn:' resource identifier. Support for this resolving is enabled by default in all Squid. This problem allows a malicious server in collaboration with a trusted client to consume arbitrarily large amounts of memory on the server running Squid. Lack of available memory resources impacts all services on the machine running Squid. Once initiated the DoS situation will persist until Squid is shutdown. This flaw was part of the 'Squid Caching Proxy Security Audit: 55 vulnerabilities and 35 0days' publication in October 2023 and filed as 'RFC 2141 / 2169 (URN) Response Parsing Memory Leak'. Affected Software/OS: Squid version 2.0 through 4.14 and 5.0.1 through 5.0.5. Solution: Update to version 4.15, 5.0.6 or later. See the referenced vendor advisory for a workaround. CVSS Score: 5.0 CVSS Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2021-28651 Debian Security Information: DSA-4924 (Google Search) https://www.debian.org/security/2021/dsa-4924 https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/T4EPIWUZDJAXADDHVOPKRBTQHPBR6H66/ https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LSQ3U54ZCNXR44QRPW3AV2VCS6K3TKCF/ http://seclists.org/fulldisclosure/2023/Oct/14 https://bugs.squid-cache.org/show_bug.cgi?id=5104 https://github.com/squid-cache/squid/security/advisories/GHSA-ch36-9jhx-phm4 https://lists.debian.org/debian-lts-announce/2021/06/msg00014.html http://www.openwall.com/lists/oss-security/2023/10/11/3 |
Copyright | Copyright (C) 2021 Greenbone AG |
This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |