← All CVEs

CVE-2021-28116

low · 3.7

Squid through 4.14 and 5.x through 5.0.5, in some configurations, allows information disclosure because of an out-of-bounds read in WCCP protocol data. This can be leveraged as part of a chain for remote code execution as nobody.

3.7
CVSS
12.9%
EPSS (exploit prob.)
96th
EPSS percentile
2021-03-09
Published

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Weaknesses

CWE-125

Affected products

VendorProductAffected versions
squid-cachesquid<= 4.14
squid-cachesquid>= 5.0, <= 5.0.5
fedoraprojectfedora33
fedoraprojectfedora34
debiandebian_linux10.0
debiandebian_linux11.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2021-28116