Security Advisory

CVE-2021-28116

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-03-09 21:44:58
Last updated 2024-08-03 21:33:17
Assigner mitre
State PUBLISHED

Description

Squid through 4.14 and 5.x through 5.0.5, in some configurations, allows information disclosure because of an out-of-bounds read in WCCP protocol data. This can be leveraged as part of a chain for remote code execution as nobody.