squid: denial of service issue in Cache Manager
Published May 27, 2021
6.8
MEDIUMCVSS 3.1
EPSS 4.34%
Description
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to incorrect parser validation, it allows a Denial of Service attack against the Cache Manager API. This allows a trusted client to trigger memory leaks that. over time, lead to a Denial of Service via an unspecified short query string. This attack is limited to clients with Cache Manager API access privilege.
Affected products
No data.
Configuration 1
- ≥ 1.0 · < 4.15
- ≥ 5.0 · < 5.0.6
Configuration 2
- 9.0
- 10.0
Configuration 3
- 33
- 34
No data.
Red Hat Enterprise Linux 8
squid:4-8050020210618131503.b4937e53
Fixed · RHSA-2021:4292
Red Hat Enterprise Linux 6
squid
Out of support scope
Red Hat Enterprise Linux 6
squid34
Out of support scope
Red Hat Enterprise Linux 7
squid
Out of support scope
Red Hat Enterprise Linux 9
squid
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | squid:4-8050020210618131503.b4937e53 | Fixed | RHSA-2021:4292 |
| Red Hat Enterprise Linux 6 | squid | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | squid34 | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | squid | Out of support scope | n/a |
| Red Hat Enterprise Linux 9 | squid | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue has been rated as having a security impact of Moderate. At this stage in their life, Red Hat Enterprise Linux 6 and 7 only accept Important and Critical Security Advisories (RHSAs) and this flaw does not meet these criteria. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata. Red Hat Satellite does not ship the Squid package, however, does consume it from RHEL 7 repository. Product is not affected by this flaw as squid.conf configuration disables all the http_access fragments except the localhost.
Red Hat mitigation
To mitigate this flaw Cache Manager access privileges can be hardened, for example by requiring authentication or other access controls in the "http_access" directive beyond the default IP address restriction. Alternatively, Cache Manager access can be disabled entirely if not needed. To do so, place the following line in `squid.conf` before lines containing "allow" : ``` http_access deny manager ```
References (12)
- http://seclists.org/fulldisclosure/2023/Oct/14 mailing-listMailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2023/10/11/3 mailing-listMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2021-28652 Vendor Advisory
- https://bugs.squid-cache.org/show_bug.cgi?id=5106 ExploitIssue TrackingVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1962246 Issue Tracking
- https://github.com/squid-cache/squid/security/advisories/GHSA-m47m-9hvw-7447 PatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/06/msg00014.html mailing-listMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LSQ3U54ZCNXR44QRPW3AV2VCS6K3TKCF/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4EPIWUZDJAXADDHVOPKRBTQHPBR6H66/ vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-28652
- https://www.cve.org/CVERecord?id=CVE-2021-28652
- https://www.debian.org/security/2021/dsa-4924 vendor-advisoryThird Party Advisory
Change history (0)
No recorded changes yet.