First published: Thu Apr 21 2016(Updated: )
Multiple stack-based buffer overflows in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote HTTP servers to cause a denial of service or execute arbitrary code via crafted Edge Side Includes (ESI) responses.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/squid | <3.5.17 | 3.5.17 |
redhat/squid | <4.0.9 | 4.0.9 |
Ubuntu Linux | =12.04 | |
Ubuntu Linux | =14.04 | |
Ubuntu Linux | =15.10 | |
Ubuntu Linux | =16.04 | |
Squid Web Proxy Cache | =3.0 | |
Squid Web Proxy Cache | =3.1 | |
Squid Web Proxy Cache | =3.1.0.1 | |
Squid Web Proxy Cache | =3.1.0.2 | |
Squid Web Proxy Cache | =3.1.0.3 | |
Squid Web Proxy Cache | =3.1.0.4 | |
Squid Web Proxy Cache | =3.1.0.5 | |
Squid Web Proxy Cache | =3.1.0.6 | |
Squid Web Proxy Cache | =3.1.0.7 | |
Squid Web Proxy Cache | =3.1.0.8 | |
Squid Web Proxy Cache | =3.1.0.9 | |
Squid Web Proxy Cache | =3.1.0.10 | |
Squid Web Proxy Cache | =3.1.0.11 | |
Squid Web Proxy Cache | =3.1.0.12 | |
Squid Web Proxy Cache | =3.1.0.13 | |
Squid Web Proxy Cache | =3.1.0.14 | |
Squid Web Proxy Cache | =3.1.0.15 | |
Squid Web Proxy Cache | =3.1.0.16 | |
Squid Web Proxy Cache | =3.1.0.17 | |
Squid Web Proxy Cache | =3.1.0.18 | |
Squid Web Proxy Cache | =3.1.1 | |
Squid Web Proxy Cache | =3.1.2 | |
Squid Web Proxy Cache | =3.1.3 | |
Squid Web Proxy Cache | =3.1.4 | |
Squid Web Proxy Cache | =3.1.5 | |
Squid Web Proxy Cache | =3.1.5.1 | |
Squid Web Proxy Cache | =3.1.6 | |
Squid Web Proxy Cache | =3.1.7 | |
Squid Web Proxy Cache | =3.1.8 | |
Squid Web Proxy Cache | =3.1.9 | |
Squid Web Proxy Cache | =3.1.10 | |
Squid Web Proxy Cache | =3.1.11 | |
Squid Web Proxy Cache | =3.1.12 | |
Squid Web Proxy Cache | =3.1.12.1 | |
Squid Web Proxy Cache | =3.1.12.2 | |
Squid Web Proxy Cache | =3.1.12.3 | |
Squid Web Proxy Cache | =3.1.13 | |
Squid Web Proxy Cache | =3.1.14 | |
Squid Web Proxy Cache | =3.1.15 | |
Squid Web Proxy Cache | =3.1.16 | |
Squid Web Proxy Cache | =3.1.17 | |
Squid Web Proxy Cache | =3.1.18 | |
Squid Web Proxy Cache | =3.1.19 | |
Squid Web Proxy Cache | =3.1.20 | |
Squid Web Proxy Cache | =3.1.21 | |
Squid Web Proxy Cache | =3.1.22 | |
Squid Web Proxy Cache | =3.2.0.1 | |
Squid Web Proxy Cache | =3.2.0.2 | |
Squid Web Proxy Cache | =3.2.0.3 | |
Squid Web Proxy Cache | =3.2.0.4 | |
Squid Web Proxy Cache | =3.2.0.5 | |
Squid Web Proxy Cache | =3.2.0.6 | |
Squid Web Proxy Cache | =3.2.0.7 | |
Squid Web Proxy Cache | =3.2.0.8 | |
Squid Web Proxy Cache | =3.2.0.9 | |
Squid Web Proxy Cache | =3.2.0.10 | |
Squid Web Proxy Cache | =3.2.0.11 | |
Squid Web Proxy Cache | =3.2.0.12 | |
Squid Web Proxy Cache | =3.2.0.13 | |
Squid Web Proxy Cache | =3.2.0.14 | |
Squid Web Proxy Cache | =3.2.0.15 | |
Squid Web Proxy Cache | =3.2.0.16 | |
Squid Web Proxy Cache | =3.2.0.17 | |
Squid Web Proxy Cache | =3.2.0.18 | |
Squid Web Proxy Cache | =3.2.0.19 | |
Squid Web Proxy Cache | =3.2.1 | |
Squid Web Proxy Cache | =3.2.2 | |
Squid Web Proxy Cache | =3.2.3 | |
Squid Web Proxy Cache | =3.2.4 | |
Squid Web Proxy Cache | =3.2.5 | |
Squid Web Proxy Cache | =3.2.6 | |
Squid Web Proxy Cache | =3.2.7 | |
Squid Web Proxy Cache | =3.2.8 | |
Squid Web Proxy Cache | =3.2.9 | |
Squid Web Proxy Cache | =3.2.10 | |
Squid Web Proxy Cache | =3.2.11 | |
Squid Web Proxy Cache | =3.2.12 | |
Squid Web Proxy Cache | =3.2.13 | |
Squid Web Proxy Cache | =3.3.0 | |
Squid Web Proxy Cache | =3.3.0.1 | |
Squid Web Proxy Cache | =3.3.0.2 | |
Squid Web Proxy Cache | =3.3.0.3 | |
Squid Web Proxy Cache | =3.3.1 | |
Squid Web Proxy Cache | =3.3.2 | |
Squid Web Proxy Cache | =3.3.3 | |
Squid Web Proxy Cache | =3.3.4 | |
Squid Web Proxy Cache | =3.3.5 | |
Squid Web Proxy Cache | =3.3.6 | |
Squid Web Proxy Cache | =3.3.7 | |
Squid Web Proxy Cache | =3.3.8 | |
Squid Web Proxy Cache | =3.3.9 | |
Squid Web Proxy Cache | =3.3.10 | |
Squid Web Proxy Cache | =3.3.11 | |
Squid Web Proxy Cache | =3.3.12 | |
Squid Web Proxy Cache | =3.3.13 | |
Squid Web Proxy Cache | =3.3.14 | |
Squid Web Proxy Cache | =3.4.0.1 | |
Squid Web Proxy Cache | =3.4.0.2 | |
Squid Web Proxy Cache | =3.4.0.3 | |
Squid Web Proxy Cache | =3.4.1 | |
Squid Web Proxy Cache | =3.4.2 | |
Squid Web Proxy Cache | =3.4.3 | |
Squid Web Proxy Cache | =3.4.4 | |
Squid Web Proxy Cache | =3.4.4.1 | |
Squid Web Proxy Cache | =3.4.4.2 | |
Squid Web Proxy Cache | =3.4.8 | |
Squid Web Proxy Cache | =3.4.9 | |
Squid Web Proxy Cache | =3.4.10 | |
Squid Web Proxy Cache | =3.4.11 | |
Squid Web Proxy Cache | =3.4.12 | |
Squid Web Proxy Cache | =3.4.13 | |
Squid Web Proxy Cache | =3.4.14 | |
Squid Web Proxy Cache | =3.5.0.1 | |
Squid Web Proxy Cache | =3.5.0.2 | |
Squid Web Proxy Cache | =3.5.0.3 | |
Squid Web Proxy Cache | =3.5.0.4 | |
Squid Web Proxy Cache | =3.5.1 | |
Squid Web Proxy Cache | =3.5.2 | |
Squid Web Proxy Cache | =3.5.3 | |
Squid Web Proxy Cache | =3.5.4 | |
Squid Web Proxy Cache | =3.5.5 | |
Squid Web Proxy Cache | =3.5.6 | |
Squid Web Proxy Cache | =3.5.7 | |
Squid Web Proxy Cache | =3.5.8 | |
Squid Web Proxy Cache | =3.5.9 | |
Squid Web Proxy Cache | =3.5.10 | |
Squid Web Proxy Cache | =3.5.11 | |
Squid Web Proxy Cache | =3.5.12 | |
Squid Web Proxy Cache | =3.5.13 | |
Squid Web Proxy Cache | =3.5.14 | |
Squid Web Proxy Cache | =3.5.15 | |
Squid Web Proxy Cache | =3.5.16 | |
Squid Web Proxy Cache | =4.0.1 | |
Squid Web Proxy Cache | =4.0.2 | |
Squid Web Proxy Cache | =4.0.3 | |
Squid Web Proxy Cache | =4.0.4 | |
Squid Web Proxy Cache | =4.0.5 | |
Squid Web Proxy Cache | =4.0.6 | |
Squid Web Proxy Cache | =4.0.7 | |
Squid Web Proxy Cache | =4.0.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2016-4052 is high due to its potential to cause denial of service and execute arbitrary code.
To fix CVE-2016-4052, upgrade Squid to version 3.5.17 or 4.0.9 or later.
CVE-2016-4052 affects Squid versions prior to 3.5.17 and 4.x prior to 4.0.9.
CVE-2016-4052 exploits multiple stack-based buffer overflows in Squid by sending crafted Edge Side Includes (ESI) responses.
While upgrading is the best solution, temporary measures may include limiting external access to Squid or configuring firewall rules to manage incoming HTTP responses.