I'm forwarding this to bug-guix@gnu.org so that it won't be forgotten.
Mark
-------------------- Start of forwarded message --------------------To: guix-devel@gnu.org
CVE-2021-28116 09.03.21 23:15Squid through 4.14 and 5.x through 5.0.5, in some configurations,allows information disclosure because of an out-of-bounds read in WCCPprotocol data. This can be leveraged as part of a chain for remote codeexecution as nobody.Upstream did not release a patch yet. CVE entry to be monitored for afix.https://www.zerodayinitiative.com/advisories/ZDI-21-157/- says it is alow impact issue. -----BEGIN PGP SIGNATURE-----
iQIzBAABCgAdFiEEFIvLi9gL+xax3g6RRaix6GvNEKYFAmBIEVsACgkQRaix6GvNEKaENg//WHFfXzBXiUC10FojZyGYBpRsZ6325sj2VKok2q8eA1KkEdnMWwaGsbxC8Nl7mpoxpXB7FrwfjduC8Ayk+9oFKhwYXBI6g7XduaoQjE+xUgtNJpUH0pYNPU3dWmDmORJNFw5UWu5Ah0IoJxEubX/+M8HkdpjsMydXiNfESgUOXhPRvUxfDJfFQAlivJvpy1TdkP1UvPq3MeYU8Y6p4bZsNCzAdXh5sE/ykab93ih40TvhU/vOLMT+etkDlAXiimj9LT2yheaXONTCVDDzBwnrlhYcr1VvBYhDTbMQ1Fp2kxzEINXVofguEbtV7MENcv0mtEEAxIFEW4jNonhdwLgiilCYIo3UGOphCurXZA665edWgFLEd/ztI8VA8QvyqqVJagutBJFP4R286OBeBzuQqfNOzFkZZCEzXlhDnBisnxfSe5t6t9Kp0ILCe9+6KDu4JvhjwuxHIVNdd4xXB/hmUFznkbTCHigZsV39tuOV7K7HHG+hIyhXzULtKhCWHscQ/gfp7XUHmcfGxvIXgEqkbJvV+KhnerBHfjL+hSbHP4EX3IaVD15M8ojDUKUVa3JqpIznPCbX/lt3oW6VjjW6cu+EwHhWmPb0EmYZmpnkhbz3NHgdHZzTAnvfULPqfIelpMEQxp3TmAT43x8XY2DlL2NxfODO/pX06V/UxX3YAPc==1gPu-----END PGP SIGNATURE-----
-------------------- End of forwarded message --------------------