Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 858845 (CVE-2021-46784) - <net-proxy/squid-5.7: DoS via long Gopher server responses
Summary: <net-proxy/squid-5.7: DoS via long Gopher server responses
Status: IN_PROGRESS
Alias: CVE-2021-46784
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://github.com/squid-cache/squid/...
Whiteboard: B3 [glsa? cleanup]
Keywords:
Depends on: 889958
Blocks:
  Show dependency tree
 
Reported: 2022-07-18 17:49 UTC by John Helmert III
Modified: 2023-01-25 20:31 UTC (History)
7 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-07-18 17:49:54 UTC
CVE-2021-46784:

In Squid 3.x through 3.5.28, 4.x through 4.17, and 5.x before 5.6, due to improper buffer management, a Denial of Service can occur when processing long Gopher server responses.
Comment 1 Larry the Git Cow gentoo-dev 2022-09-29 02:15:01 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=69e685162ba2ccf86cf04e7ba544718bc9ae41d4

commit 69e685162ba2ccf86cf04e7ba544718bc9ae41d4
Author:     Sam James <sam@gentoo.org>
AuthorDate: 2022-09-24 06:19:24 +0000
Commit:     Sam James <sam@gentoo.org>
CommitDate: 2022-09-29 02:14:37 +0000

    net-proxy/squid: add 5.7
    
    Bug: https://bugs.gentoo.org/858845
    Bug: https://bugs.gentoo.org/872551
    Closes: https://bugs.gentoo.org/706126
    Closes: https://bugs.gentoo.org/869968
    Signed-off-by: Sam James <sam@gentoo.org>

 net-proxy/squid/Manifest         |   1 +
 net-proxy/squid/squid-5.7.ebuild | 362 +++++++++++++++++++++++++++++++++++++++
 2 files changed, 363 insertions(+)