PT-2016-1432 · Squid+5 · Squid+6

Mathias Fischer

·

Published

2014-04-24

·

Updated

2024-06-15

·

CVE-2016-2569

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Squid versions 3.x through 3.5.14 Squid versions 4.x through 4.0.6
Description The issue allows remote servers to cause a denial of service via a long string, as demonstrated by a crafted HTTP Vary header. This occurs because Squid does not properly append data to String objects, leading to an assertion failure and daemon exit.
Recommendations For Squid versions 3.x through 3.5.14, update to version 3.5.15 or later. For Squid versions 4.x through 4.0.6, update to version 4.0.7 or later.

Exploit

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1531
ALT-PU-2015-1085
ALT-PU-2015-1383
ALT-PU-2015-1900
ALT-PU-2016-1444
ALT-PU-2016-2464
ALT-PU-2018-2314
BDU:2016-00733
CESA-2015_2378
CESA-2016_2600
CESA-2017_0182
CESA-2017_0183
CESA-2020_1068
CVE-2016-2569
ELSA-2016-2600
MGASA-2016-0095
OPENSUSE-SU-2024:11403-1
RHSA-2015_2378
RHSA-2016:2600
RHSA-2016_2600
RHSA-2017_0182
RHSA-2017_0183
RHSA-2020_1068
SUSE-SU-2016:2008-1
SUSE-SU-2016:2089-1
SUSE-SU-2016_1996-1
SUSE-SU-2016_2008-1
SUSE-SU-2016_2089-1
USN-3557-1

Affected Products

Alt Linux
Centos
Red Hat
Squid
Squid Cache
Suse
Ubuntu