Описание
Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not properly append data to String objects, which allows remote servers to cause a denial of service (assertion failure and daemon exit) via a long string, as demonstrated by a crafted HTTP Vary header.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
squid3 | fixed | 3.5.15-1 | package | |
squid3 | no-dsa | wheezy | package | |
squid | not-affected | package |
Примечания
http://www.squid-cache.org/Advisories/SQUID-2016_2.txt
http://www.squid-cache.org/Versions/v3/3.5/changesets/squid-3.5-13991.patch
http://www.squid-cache.org/Versions/v3/3.5/changesets/squid-3.5-13998.patch
http://www.squid-cache.org/Versions/v3/3.5/changesets/squid-3.5-13999.patch
http://www.squid-cache.org/Versions/v4/changesets/squid-4-14552.patch
Upstream confirmed it does not affect squid 2.7.x
EPSS
Связанные уязвимости
Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not properly append data to String objects, which allows remote servers to cause a denial of service (assertion failure and daemon exit) via a long string, as demonstrated by a crafted HTTP Vary header.
Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not properly append data to String objects, which allows remote servers to cause a denial of service (assertion failure and daemon exit) via a long string, as demonstrated by a crafted HTTP Vary header.
Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not properly append data to String objects, which allows remote servers to cause a denial of service (assertion failure and daemon exit) via a long string, as demonstrated by a crafted HTTP Vary header.
Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not properly append data to String objects, which allows remote servers to cause a denial of service (assertion failure and daemon exit) via a long string, as demonstrated by a crafted HTTP Vary header.
Уязвимость прокси-сервера Squid, позволяющая нарушителю вызвать отказ в обслуживании
EPSS