CVE-2021-41611
high
CVSS v3
—
CVSS v2
—
VIR risk
8.0
Description
An issue was discovered in Squid 5.0.6 through 5.1.x before 5.2. When validating an origin server or peer certificate, Squid may incorrectly classify certain certificates as trusted. This problem allows a remote server to obtain security trust well improperly. This indication of trust may be passed along to clients, allowing access to unsafe or hijacked services.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2021-41611
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| arch | fixed | 5.2-1 | |
| debian | bookworm | fixed | 5.2-1 |
| debian | bullseye | fixed | 0 |
| debian | forky | fixed | 5.2-1 |
| debian | sid | fixed | 5.2-1 |
| debian | trixie | fixed | 5.2-1 |
References
Verify integrity in audit chain (admin only). AS-IS.