Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.146940
Category:Denial of Service
Title:Squid Certificate Validation Vulnerability (SQUID-2021:6, GHSA-47m4-g3mv-9q5r)
Summary:Squid is prone to a certificate validation vulnerability.
Description:Summary:
Squid is prone to a certificate validation vulnerability.

Vulnerability Insight:
When validating an origin server or peer certificate, Squid may
incorrectly classify certain certificates as trusted.

This problem is guaranteed to occur when multiple CA have signed the TLS server certificate. It
may also occur in cases of broken server certificate chains.

Vulnerability Impact:
This problem allows a remote server to obtain security trust
when the trust is not valid. This indication of trust may be passed along to clients allowing
access to unsafe or hijacked services.

Affected Software/OS:
Squid version 5.0.6 through 5.1.

Solution:
Update to version 5.2 or later.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:N/A:N

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2021-41611
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CWQ2WKDWTSO47S3F6XJJ6HGG2ULWEAE4/
http://www.squid-cache.org/Versions/v6/changesets/squid-6-43d6b5c81b88ec2256b430c69a872a1e4f324e4a.patch
http://www.openwall.com/lists/oss-security/2021/12/23/2
CopyrightCopyright (C) 2021 Greenbone Networks GmbH

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.