|Type||Denial of service|
Due to a buffer management bug Squid before version 4.15 is vulnerable to a denial of service attack against the server it is operating on. This attack is limited to proxies which attempt to resolve a "urn:" resource identifier. Support for this resolving is enabled by default in all Squid.
|19 May 2021||ASA-202105-10||AVG-1949||squid||High||denial of service|
Workaround ========== The issue can be mitigated by disabling URN processing by the proxy, by adding these lines to squid.conf: acl URN proto URN http_access deny URN