An issue was discovered in Squid 4.x before 4.15 and 5.x before 5.0.6. If a remote server sends a certain response header over HTTP or HTTPS, there is a denial of service. This header can plausibly occur in benign network traffic.
| Software | From | Fixed in |
|---|---|---|
| squid-cache / squid | 5.0 | 5.0.6 |
| squid-cache / squid | 4.0.1 | 4.15 |
| debian / debian_linux | 10.0 | 10.0.x |
| fedoraproject / fedora | 33 | 33.x |
| fedoraproject / fedora | 34 | 34.x |