CVE-2021-33620
Published · Updated
35Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.5epss 80%
exploitation probability
80%top 1% of all CVEs
observed exploitation
nono source reports it
What the vendors declare (VEX)
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Red HatVEX document ↗
Affected
2 products (8 components)
Red Hat Enterprise Linux 6 · Red Hat Enterprise Linux 7
workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Fixed
Not affected
1 product (2 components) — because the vulnerable code is not present in the product
Red Hat Enterprise Linux 9
Squid before 4.15 and 5.x before 5.0.6 allows remote servers to cause a denial of service (affecting availability to all clients) via an HTTP response. The issue trigger is a header that can be expected to exist in HTTP traffic without any malicious intent by the server.
CVSS:3.1/AC:L/AV:N/A:H/C:N/I:N/PR:L/S:U/UI:N
Affected products
n/a · n/aReferences
http://seclists.org/fulldisclosure/2023/Oct/14https://github.com/squid-cache/squid/security/advisories/GHSA-572g-rvwr-6c7fhttps://lists.debian.org/debian-lts-announce/2021/06/msg00014.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LSQ3U54ZCNXR44QRPW3AV2VCS6K3TKCF/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T4EPIWUZDJAXADDHVOPKRBTQHPBR6H66/http://www.openwall.com/lists/oss-security/2023/10/11/3http://www.squid-cache.org/Versions/v4/changesets/squid-4-1e05a85bd28c22c9ca5d3ac9f5e86d6269ec0a8c.patchhttp://www.squid-cache.org/Versions/v5/changesets/squid-5-8af775ed98bfd610f9ce762fe177e01b2675588c.patch