Bug 1939939 (CVE-2021-28116) - CVE-2021-28116 squid: out-of-bounds read in WCCP protocol data may lead to information disclosure
Summary: CVE-2021-28116 squid: out-of-bounds read in WCCP protocol data may lead to in...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2021-28116
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
: 1934558 (view as bug list)
Depends On: 1939940 1941505 1941506
Blocks: 1934571
TreeView+ depends on / blocked
 
Reported: 2021-03-17 10:28 UTC by Marian Rehak
Modified: 2022-05-12 02:16 UTC (History)
10 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
A flaw was found in squid. An out-of-bounds read in the WCCP protocol can be leveraged as part of a chain for remote code execution leading to an information disclosure. The highest threat from this vulnerability is to data confidentiality.
Clone Of:
Environment:
Last Closed: 2022-05-12 02:16:02 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2022:1939 0 None None None 2022-05-10 14:24:16 UTC

Description Marian Rehak 2021-03-17 10:28:46 UTC
In some configurations, squid allows information disclosure because of an out-of-bounds read in WCCP protocol data. This can be leveraged as part of a chain for remote code execution as nobody.

Comment 1 Marian Rehak 2021-03-17 10:29:37 UTC
Created squid tracking bugs for this issue:

Affects: fedora-all [bug 1939940]

Comment 2 Mauro Matteo Cascella 2021-03-19 09:28:58 UTC
External References:

https://www.zerodayinitiative.com/advisories/ZDI-21-157/

Comment 3 Mauro Matteo Cascella 2021-03-19 09:41:24 UTC
*** Bug 1934558 has been marked as a duplicate of this bug. ***

Comment 12 errata-xmlrpc 2022-05-10 14:24:12 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2022:1939 https://access.redhat.com/errata/RHSA-2022:1939

Comment 13 Product Security DevOps Team 2022-05-12 02:16:00 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2021-28116


Note You need to log in before you can comment on or make changes to this bug.