Hide Forgot
Due to an input validation bug Squid is vulnerable to a Denial of Service against all clients using the proxy. This problem allows a remote server to perform Denial of Service when delivering HTTP Response messages. The issue trigger is a header which can be expected to exist in HTTP traffic without any malicious intent by the server. Reference: https://github.com/squid-cache/squid/security/advisories/GHSA-572g-rvwr-6c7f/
Created squid tracking bugs for this issue: Affects: fedora-all [bug 1959538]
Upstream pull request: https://github.com/squid-cache/squid/pull/791 Upstream commits: https://github.com/squid-cache/squid/commit/6c9c44d0e9cf7b72bb233360c5308aa063af3d69 [master] https://github.com/squid-cache/squid/commit/8af775ed98bfd610f9ce762fe177e01b2675588c [v5] https://github.com/squid-cache/squid/commit/1e05a85bd28c22c9ca5d3ac9f5e86d6269ec0a8c [v4]
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2021:4292 https://access.redhat.com/errata/RHSA-2021:4292
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2021-33620