REDHAT-BUG-1334786: Medium severity squid web proxy cache vulnerability
Due to incorrect reference counting Squid is vulnerable to a denial of service attack when processing ESI responses.
External references:
http://www.squid-cache.org/Advisories/SQUID-20169.txt
Upstream fixes:
Squid 3.5:
http://www.squid-cache.org/Versions/v3/3.5/changesets/SQUID-20169.patch
Squid 3.4:
http://www.squid-cache.org/Versions/v3/3.4/changesets/SQUID-20169.patch
NOTE: For the other related CVE, CVE-2016-4555, see Bug 1334246
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1334786?
REDHAT-BUG-1334786 has a high severity due to its potential to cause a denial of service attack.
How do I fix REDHAT-BUG-1334786?
To fix REDHAT-BUG-1334786, update to Squid version 3.5 or later.
Which versions of Squid are affected by REDHAT-BUG-1334786?
REDHAT-BUG-1334786 affects Squid versions 3.4 and 3.5.
What type of vulnerability is REDHAT-BUG-1334786?
REDHAT-BUG-1334786 is a denial of service vulnerability due to incorrect reference counting.
Where can I find more information about REDHAT-BUG-1334786?
More information about REDHAT-BUG-1334786 can be found in the Squid advisory.