Red Hat Enterprise Linux 8.6 update for the squid:4 module

This security bulletin contains one medium risk vulnerability.


1) Reachable Assertion


EUVDB-ID: #VU64484


Risk: Medium


CVSSv3.1: 5.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]


CVE-ID: CVE-2021-46784


CWE-ID: CWE-617 - Reachable Assertion


Exploit availability: No


Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.


The vulnerability exists due to a reachable assertion when processing Gopher server responses. A remote attacker can send a specially crafted response to the proxy server and perform a denial of service (DoS) attack.


Mitigation

Install updates from vendor's website.


Vulnerable software versions

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions: 8.6


Red Hat Enterprise Linux for ARM 64 - Extended Update Support: 8.6


Red Hat Enterprise Linux Server - TUS: 8.6


Red Hat Enterprise Linux for Power, little endian - Extended Update Support: 8.6


Red Hat Enterprise Linux for IBM z Systems - Extended Update Support: 8.6


Red Hat Enterprise Linux Server - AUS: 8.6


Red Hat Enterprise Linux for x86_64 - Extended Update Support: 8.6


Red Hat Enterprise Linux for ARM 64: 8


Red Hat Enterprise Linux for Power, little endian: 8


Red Hat Enterprise ..

Support the originator by clicking the read the rest link below.