Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-2571

Опубликовано: 27 фев. 2016
Источник: debian
EPSS Средний

Описание

http.cc in Squid 3.x before 3.5.15 and 4.x before 4.0.7 proceeds with the storage of certain data after a response-parsing failure, which allows remote HTTP servers to cause a denial of service (assertion failure and daemon exit) via a malformed response.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
squid3fixed3.5.15-1package
squidnot-affectedpackage

Примечания

  • http://www.squid-cache.org/Advisories/SQUID-2016_2.txt

  • http://www.squid-cache.org/Versions/v3/3.5/changesets/squid-3.5-13990.patch

  • http://www.squid-cache.org/Versions/v4/changesets/squid-4-14548.patch

  • Upstream confirmed it does not affect squid 2.7.x

EPSS

Процентиль: 94%
0.15571
Средний

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 9 лет назад

http.cc in Squid 3.x before 3.5.15 and 4.x before 4.0.7 proceeds with the storage of certain data after a response-parsing failure, which allows remote HTTP servers to cause a denial of service (assertion failure and daemon exit) via a malformed response.

redhat
больше 9 лет назад

http.cc in Squid 3.x before 3.5.15 and 4.x before 4.0.7 proceeds with the storage of certain data after a response-parsing failure, which allows remote HTTP servers to cause a denial of service (assertion failure and daemon exit) via a malformed response.

CVSS3: 7.5
nvd
больше 9 лет назад

http.cc in Squid 3.x before 3.5.15 and 4.x before 4.0.7 proceeds with the storage of certain data after a response-parsing failure, which allows remote HTTP servers to cause a denial of service (assertion failure and daemon exit) via a malformed response.

CVSS3: 7.5
github
больше 3 лет назад

http.cc in Squid 3.x before 3.5.15 and 4.x before 4.0.7 proceeds with the storage of certain data after a response-parsing failure, which allows remote HTTP servers to cause a denial of service (assertion failure and daemon exit) via a malformed response.

fstec
больше 9 лет назад

Уязвимость прокси-сервера Squid, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 94%
0.15571
Средний