Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-4051

Опубликовано: 20 апр. 2016
Источник: redhat
CVSS2: 5.1
EPSS Низкий

Описание

Buffer overflow in cachemgr.cgi in Squid 2.x, 3.x before 3.5.17, and 4.x before 4.0.9 might allow remote attackers to cause a denial of service or execute arbitrary code by seeding manager reports with crafted data.

A buffer overflow flaw was found in the way the Squid cachemgr.cgi utility processed remotely relayed Squid input. When the CGI interface utility is used, a remote attacker could possibly use this flaw to execute arbitrary code.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5squidWill not fix
Red Hat Enterprise Linux 6squidFixedRHSA-2016:113831.05.2016
Red Hat Enterprise Linux 6squid34FixedRHSA-2016:114031.05.2016
Red Hat Enterprise Linux 7squidFixedRHSA-2016:113931.05.2016

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=1329126squid: buffer overflow in cachemgr.cgi

EPSS

Процентиль: 81%
0.01597
Низкий

5.1 Medium

CVSS2

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 9 лет назад

Buffer overflow in cachemgr.cgi in Squid 2.x, 3.x before 3.5.17, and 4.x before 4.0.9 might allow remote attackers to cause a denial of service or execute arbitrary code by seeding manager reports with crafted data.

CVSS3: 8.8
nvd
больше 9 лет назад

Buffer overflow in cachemgr.cgi in Squid 2.x, 3.x before 3.5.17, and 4.x before 4.0.9 might allow remote attackers to cause a denial of service or execute arbitrary code by seeding manager reports with crafted data.

CVSS3: 8.8
debian
больше 9 лет назад

Buffer overflow in cachemgr.cgi in Squid 2.x, 3.x before 3.5.17, and 4 ...

CVSS3: 8.8
github
больше 3 лет назад

Buffer overflow in cachemgr.cgi in Squid 2.x, 3.x before 3.5.17, and 4.x before 4.0.9 might allow remote attackers to cause a denial of service or execute arbitrary code by seeding manager reports with crafted data.

suse-cvrf
около 9 лет назад

Security update for squid

EPSS

Процентиль: 81%
0.01597
Низкий

5.1 Medium

CVSS2