Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Debian DSA-3625-1 Critical: Squid3 DoS and Buffer Overflow Threats

debian
Calendar Grey July 22, 2016
Debian Logo
Debian releases for squid3 tackle numerous problems such as Denial of Service and buffer overflow risks.
Several security issues have been discovered in the Squid caching proxy

Summary

CVE-2016-4051:

CESG and Yuriy M. Kaminskiy discovered that Squid cachemgr.cgi was
vulnerable to a buffer overflow when processing remotely supplied
inputs relayed through Squid.

CVE-2016-4052:

CESG discovered that a buffer overflow made Squid vulnerable to a
Denial of Service (DoS) attack when processing ESI responses.

CVE-2016-4053:

CESG found that Squid was vulnerable to public information
disclosure of the server stack layout when processing ESI responses.

CVE-2016-4054:

CESG discovered that Squid was vulnerable to remote code execution
when processing ESI responses.

CVE-2016-4554:

Jianjun Chen found that Squid was vulnerable to a header smuggling
attack that could lead to cache poisoning and to bypass of
same-origin security policy in Squid and some client browsers.

CVE-2016-4555, CVE-2016-4556:

"bfek-18" and "@vftable" found that Squid was vulnerable to a Denial
of Service (DoS) attack when processing ESI responses, due to
incorrect pointer handling and reference coun...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: squid3
CVE ID: CVE-2016-4051 CVE-2016-4052 CVE-2016-4053 CVE-2016-4054

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here