CLSA-2022-1646060698

See a problem?
Import Source
https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.4els/CLSA-2022-1646060698.json
JSON Data
https://api.test.osv.dev/v1/vulns/CLSA-2022-1646060698
Upstream
Published
2022-02-28T15:04:58Z
Modified
2026-05-27T11:33:40.562693855Z
Summary
Fix of CVE: CVE-2021-31807, CVE-2021-28662, CVE-2021-33620, CVE-2021-28652, CVE-2021-28651, CVE-2021-31808, CVE-2021-31806
Details
  • CVE-2021-28651: Fix memory leak that perform DoS via buffer-management bug
  • CVE-2021-28652: Fix cache manager URL parsing that perform DoS via incorrect parser validation
  • CVE-2021-28662: Add limit HeaderLookupTable_t::lookup() to BadHdr and specific IDs that perform DoS via certain response header
  • CVE-2021-31806: Add handling more partial responses that perform DoS via HTTP Range request
  • CVE-2021-31807: Add handling more partial responses that perform DoS via HTTP Range request
  • CVE-2021-31808: Add handling more partial responses that perform DoS via HTTP Range request
  • CVE-2021-33620: Add handling more partial responses that perform DoS via HTTP response
References

Affected packages

TuxCare:CentOS:8.4 / libecap

Package

Name
libecap
Purl
pkg:rpm/tuxcare/libecap?distro=centos-8.4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.1-2.module_el8.4.0+2010+24c223d9

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.4els/CLSA-2022-1646060698.json"

TuxCare:CentOS:8.4 / libecap-devel

Package

Name
libecap-devel
Purl
pkg:rpm/tuxcare/libecap-devel?distro=centos-8.4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.1-2.module_el8.4.0+2010+24c223d9

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.4els/CLSA-2022-1646060698.json"

TuxCare:CentOS:8.4 / squid

Package

Name
squid
Purl
pkg:rpm/tuxcare/squid?distro=centos-8.4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
7:4.11-4.module_el8.4.0+2010+24c223d9.2.tuxcare.els1

Database specific

source
"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/centos8.4els/CLSA-2022-1646060698.json"