PT-2016-5773 · Squid+5 · Squid+6

Santiago Ruano Rincón

·

Publicado

2014-04-24

·

Atualizado

2018-03-16

·

CVE-2016-3948

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Squid versions 3.x through 3.5.15 Squid versions 4.x through 4.0.7
Description The issue is related to improper bounds checking, which can be exploited by remote attackers to cause a denial of service via a crafted HTTP response. This is specifically related to Vary headers.
Recommendations For Squid versions 3.x through 3.5.15, update to version 3.5.16 or later. For Squid versions 4.x through 4.0.7, update to version 4.0.8 or later.

Exploit

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2014-1531
ALT-PU-2016-1444
CESA-2016_2600
CVE-2016-3948
DSA-3625-1
MGASA-2016-0133
RHSA-2016:2600
RHSA-2016_2600
SUSE-SU-2016:2008-1
SUSE-SU-2016:2089-1
USN-3557-1

Produtos afetados

Alt Linux
Centos
Red Hat
Squid
Squid Cache
Suse
Ubuntu