In Squid 3.x through 3.5.28, 4.x through 4.17, and 5.x before 5.6, due to improper buffer management, a Denial of Service can occur when processing long Gopher server responses.
{ "vanir_signatures": [ { "id": "CVE-2021-46784-01810d80", "digest": { "threshold": 0.9, "line_hashes": [ "13124783738520294387122075587809643820", "115923823867099938906874782973523574430", "94176114589957359507199599998518424517", "274977082621377609007893331183207467320", "326944887767546635409112326187408158172", "118077218092707899369457502259780153675", "11392715957146171133002480955151239589", "7108144494288769788643433600508289851", "278401408903419339614801883875193482385", "47086078884500772332109304663274528726", "36165590790211092546602452715140633540", "53803634117329376348140893914487513779", "183035891221340922906773914299954095518", "118908349958174827908154118196211494386", "235275655941132743778404614242185853759", "220983909332043003756985711762302731444", "112222650624639445787427921868800471679", "89423354348451111212535870400351634844", "336662990902233906387508948558700282683", "328832038316255072814770803101543308756", "55825358428117252454084605287656145833", "149977315569630693896859072671474703338", "2315706031118605201305542734097259052", "225598083073185892585468507028871217304", "138690528796318419605791197095472481070", "54513255579585281735845742677858834286", "212630606258933052783305110649659332444", "236471352302375339582580763156851290577", "160418389388999701011085631663522801219", "186688387659168918349349690253835939353", "321674346053248937144733360996720008958", "279515024970642496220045255435546109735", "134661006999943121819109183904413382713", "272613848798631255941155953538687507184", "324925446403978098896557902088368020970", "211923122287006986501699460157115882733", "252935344932650398932598264365479772113", "18942574542254674337861279334464865503", "263481830612776662136037837089945978086", "20747230505122173644350036526025366471", "61864829436994029161631352164722157372", "237998407588399780749174474398610322803", "68828881545218290373243218612939408260", "246040594449409312085890662639579358390", "107468142861186422461970779314782411204", "256778840515540688320006783323055282741", "199346876999600431421789942830439075459", "73342966507704218519621655118571868221", "100607674149811170452632539539335330018", "186328700864024663402034150772433027557", "324642670792422475476757576736623726327", "25523392985587464676366915932477319550", "169690349476604574206764447281033598655", "85258812759861249394735681405200249394", "273543527631926404307276941390174506420", "179717529279834891293921147312566150839", "213898650025930163164189634983313239715", "4120415116524143482957962496157887464", "145757150609783541797461748033783530200", "151567726560542897992320688062573159607", "158331498850698070496950386538212857530", "113005471972511323907382955523516626074", "337625326255853171311861208317302421355" ] }, "signature_version": "v1", "deprecated": false, "target": { "file": "src/gopher.cc" }, "signature_type": "Line", "source": "https://github.com/squid-cache/squid/commit/5e2ea2b13bd98f53e29964ca26bb0d602a8a12b9" }, { "id": "CVE-2021-46784-75296bdc", "digest": { "length": 6595.0, "function_hash": "63899508942904651983784718535806986154" }, "signature_version": "v1", "deprecated": false, "target": { "file": "src/gopher.cc", "function": "gopherToHTML" }, "signature_type": "Function", "source": "https://github.com/squid-cache/squid/commit/5e2ea2b13bd98f53e29964ca26bb0d602a8a12b9" } ] }