Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-4556

Опубликовано: 06 мая 2016
Источник: redhat
CVSS2: 4.3
EPSS Средний

Описание

Double free vulnerability in Esi.cc in Squid 3.x before 3.5.18 and 4.x before 4.0.10 allows remote servers to cause a denial of service (crash) via a crafted Edge Side Includes (ESI) response.

An incorrect reference counting flaw was found in the way Squid processes ESI responses. If Squid is configured as reverse-proxy, for TLS/HTTPS interception, an attacker controlling a server accessed by Squid, could crash the squid worker, causing a Denial of Service attack.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5squidNot affected
Red Hat Enterprise Linux 6squidFixedRHSA-2016:113831.05.2016
Red Hat Enterprise Linux 6squid34FixedRHSA-2016:114031.05.2016
Red Hat Enterprise Linux 7squidFixedRHSA-2016:113931.05.2016

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1334786squid: SIGSEGV in ESIContext response handling

EPSS

Процентиль: 97%
0.39329
Средний

4.3 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 9 лет назад

Double free vulnerability in Esi.cc in Squid 3.x before 3.5.18 and 4.x before 4.0.10 allows remote servers to cause a denial of service (crash) via a crafted Edge Side Includes (ESI) response.

CVSS3: 7.5
nvd
больше 9 лет назад

Double free vulnerability in Esi.cc in Squid 3.x before 3.5.18 and 4.x before 4.0.10 allows remote servers to cause a denial of service (crash) via a crafted Edge Side Includes (ESI) response.

CVSS3: 7.5
debian
больше 9 лет назад

Double free vulnerability in Esi.cc in Squid 3.x before 3.5.18 and 4.x ...

CVSS3: 7.5
github
больше 3 лет назад

Double free vulnerability in Esi.cc in Squid 3.x before 3.5.18 and 4.x before 4.0.10 allows remote servers to cause a denial of service (crash) via a crafted Edge Side Includes (ESI) response.

oracle-oval
больше 9 лет назад

ELSA-2016-1138: squid security update (MODERATE)

EPSS

Процентиль: 97%
0.39329
Средний

4.3 Medium

CVSS2