7.5
CVSSv3

CVE-2016-2571

Published: 27/02/2016 Updated: 16/03/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

http.cc in Squid 3.x prior to 3.5.15 and 4.x prior to 4.0.7 proceeds with the storage of certain data after a response-parsing failure, which allows remote HTTP servers to cause a denial of service (assertion failure and daemon exit) via a malformed response.

Vulnerable Product Search on Vulmon Subscribe to Product

squid-cache squid 3.5.0.4

squid-cache squid 3.5.0.3

squid-cache squid 3.4.2

squid-cache squid 3.4.13

squid-cache squid 3.4.0.1

squid-cache squid 3.3.9

squid-cache squid 4.0.4

squid-cache squid 4.0.3

squid-cache squid 3.4.9

squid-cache squid 3.4.8

squid-cache squid 3.4.10

squid-cache squid 3.4.1

squid-cache squid 3.3.6

squid-cache squid 3.3.5

squid-cache squid 3.3.4

squid-cache squid 3.3.1

squid-cache squid 3.3.0.3

squid-cache squid 3.2.5

squid-cache squid 3.2.4

squid-cache squid 3.2.0.9

squid-cache squid 3.2.0.8

squid-cache squid 3.2.0.19

squid-cache squid 3.2.0.18

squid-cache squid 3.2.0.11

squid-cache squid 3.2.0.10

squid-cache squid 3.1.4

squid-cache squid 3.1.3

squid-cache squid 3.1.10

squid-cache squid 3.1.1

squid-cache squid 3.1.0.3

squid-cache squid 3.1.0.2

squid-cache squid 3.1.0.11

squid-cache squid 3.1.0.10

squid-cache squid 3.0.stable5

squid-cache squid 3.0.stable4

squid-cache squid 3.0.stable20

squid-cache squid 3.0.stable2

squid-cache squid 3.3.13

squid-cache squid 3.3.12

squid-cache squid 3.2.9

squid-cache squid 3.2.8

squid-cache squid 3.2.13

squid-cache squid 3.2.12

squid-cache squid 3.2.0.5

squid-cache squid 3.2.0.4

squid-cache squid 3.2.0.15

squid-cache squid 3.2.0.14

squid-cache squid 3.1.8

squid-cache squid 3.1.7

squid-cache squid 3.1.6

squid-cache squid 3.1.14

squid-cache squid 3.1.13

squid-cache squid 3.1.0.7

squid-cache squid 3.1.0.6

squid-cache squid 3.1.0.16

squid-cache squid 3.1.0.15

squid-cache squid 3.1.0.14

squid-cache squid 3.0.stable9

squid-cache squid 3.0.stable8

squid-cache squid 3.0.stable24

squid-cache squid 3.0.stable23

squid-cache squid 3.0.stable16

squid-cache squid 3.0.stable10

squid-cache squid 3.0.stable1

squid-cache squid 3.0

squid-cache squid 4.0.2

squid-cache squid 4.0.1

squid-cache squid 3.5.1

squid-cache squid 3.4.4

squid-cache squid 3.4.3

squid-cache squid 3.4.0.3

squid-cache squid 3.4.0.2

squid-cache squid 3.3.3

squid-cache squid 3.3.2

squid-cache squid 3.3.0.2

squid-cache squid 3.3.0

squid-cache squid 3.2.3

squid-cache squid 3.2.2

squid-cache squid 3.2.0.7

squid-cache squid 3.2.0.6

squid-cache squid 3.2.0.17

squid-cache squid 3.2.0.16

squid-cache squid 3.2.0.1

squid-cache squid 3.1.9

squid-cache squid 3.1.2

squid-cache squid 3.1.15

squid-cache squid 3.1.0.9

squid-cache squid 3.1.0.8

squid-cache squid 3.1.0.18

squid-cache squid 3.1.0.17

squid-cache squid 3.1.0.1

squid-cache squid 3.1

squid-cache squid 3.0.stable3

squid-cache squid 3.0.stable25

squid-cache squid 3.0.stable19

squid-cache squid 3.0.stable18

squid-cache squid 3.0.stable17

squid-cache squid 3.0.stable11

squid-cache squid 4.0.6

squid-cache squid 4.0.5

squid-cache squid 3.5.0.2

squid-cache squid 3.5.0.1

squid-cache squid 3.4.12

squid-cache squid 3.4.11

squid-cache squid 3.3.8

squid-cache squid 3.3.7

squid-cache squid 3.3.11

squid-cache squid 3.3.10

squid-cache squid 3.2.7

squid-cache squid 3.2.6

squid-cache squid 3.2.11

squid-cache squid 3.2.10

squid-cache squid 3.2.1

squid-cache squid 3.2.0.3

squid-cache squid 3.2.0.2

squid-cache squid 3.2.0.13

squid-cache squid 3.2.0.12

squid-cache squid 3.1.5.1

squid-cache squid 3.1.5

squid-cache squid 3.1.12

squid-cache squid 3.1.11

squid-cache squid 3.1.0.5

squid-cache squid 3.1.0.4

squid-cache squid 3.1.0.13

squid-cache squid 3.1.0.12

squid-cache squid 3.0.stable7

squid-cache squid 3.0.stable6

squid-cache squid 3.0.stable22

squid-cache squid 3.0.stable21

squid-cache squid 3.0.stable15

squid-cache squid 3.0.stable14

squid-cache squid 3.0.stable13

squid-cache squid 3.0.stable12

Vendor Advisories

Debian Bug report logs - #816011 squid3: CVE-2016-2569 CVE-2016-2570 CVE-2016-2571 Package: src:squid3; Maintainer for src:squid3 is Luigi Gangitano <luigi@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 26 Feb 2016 16:36:01 UTC Severity: important Tags: fixed-upstream, patch, security, ...
Alex Rousskov from The Measurement Factory discovered that Squid3, a fully featured web proxy cache, does not properly handle errors for certain malformed HTTP responses A remote HTTP server can exploit this flaw to cause a denial of service (assertion failure and daemon exit) For the oldstable distribution (wheezy), this problem has been fixed i ...
Several security issues were fixed in Squid ...
Several security issues were fixed in Squid ...
USN-3557-1 introduced a regression in Squid ...
It was found that squid did not properly handle errors when failing to parse an HTTP response, possibly leading to an assertion failure A malicious HTTP server could use this flaw to crash squid using a specially crafted HTTP response ...