Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Ubuntu 16.04 LTS: USN-2995-1 Critical: Squid Denial Of Service

ubuntu
Calendar Grey June 9, 2016
Scroller Ubuntu
Uncover remedies for several Squid vulnerabilities impacting Ubuntu. Keep your devices secure and up-to-date.
Several security issues were fixed in Squid.

Summary

Several security issues were fixed in Squid.

Software Description:

- squid3: Web proxy cache server

Details:

Yuriy M. Kaminskiy discovered that the Squid pinger utility incorrectly

handled certain ICMPv6 packets. A remote attacker could use this issue to

cause Squid to crash, resulting in a denial of service, or possibly cause

Squid to leak information into log files. (CVE-2016-3947)

Yuriy M. Kaminskiy discovered that the Squid cachemgr.cgi tool incorrectly

handled certain crafted data. A remote attacker could use this issue to

cause Squid to crash, resulting in a denial of service, or possibly execute

arbitrary code. (CVE-2016-4051)

It was discovered that Squid incorrectly handled certain Edge Side Includes

(ESI) responses. A remote attacker could possibly use this issue to cause

Squid to crash, resulting in a denial of service, or possibly execute

arbitrary code. (CVE-2016-4052, CVE-2016-4053, CVE-2016-4054)

Jianjun Chen discovered that Squid did not ...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS:
  squid-cgi                       3.5.12-1ubuntu7.2
  squid3                          3.5.12-1ubuntu7.2

Ubuntu 15.10:
  squid-cgi                       3.3.8-1ubuntu16.3
  squid3                          3.3.8-1ubuntu16.3

Ubuntu 14.04 LTS:
  squid-cgi                       3.3.8-1ubuntu6.8
  squid3                          3.3.8-1ubuntu6.8

Ubuntu 12.04 LTS:
  squid-cgi                       3.1.19-1ubuntu3.12.04.7
  squid3                          3.1.19-1ubuntu3.12.04.7

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2995-1

CVE-2016-3947, CVE-2016-4051, CVE-2016-4052, CVE-2016-4053,

CVE-2016-4054, CVE-2016-4553, CVE-2016-4554, CVE-2016-4555,

CVE-2016-4556

Severity
critical
Lowest
Low
Medium
High
Critical

June 09, 2016

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.