7.5
CVSSv3

CVE-2016-3948

Published: 07/04/2016 Updated: 16/03/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Squid 3.x prior to 3.5.16 and 4.x prior to 4.0.8 improperly perform bounds checking, which allows remote malicious users to cause a denial of service via a crafted HTTP response, related to Vary headers.

Vulnerable Product Search on Vulmon Subscribe to Product

squid-cache squid 4.0.1

squid-cache squid 3.2.7

squid-cache squid 3.5.2

squid-cache squid 3.5.10

squid-cache squid 3.5.6

squid-cache squid 3.5.7

squid-cache squid 3.4.13

squid-cache squid 3.4.12

squid-cache squid 3.3.9

squid-cache squid 3.3.8

squid-cache squid 3.3.12

squid-cache squid 3.3.11

squid-cache squid 3.2.8

squid-cache squid 3.5.15

squid-cache squid 3.2.12

squid-cache squid 3.2.11

squid-cache squid 3.2.10

squid-cache squid 3.2.0.4

squid-cache squid 3.2.0.3

squid-cache squid 3.2.0.14

squid-cache squid 3.2.0.13

squid-cache squid 3.1.7

squid-cache squid 3.1.6

squid-cache squid 3.1.5.1

squid-cache squid 3.1.13

squid-cache squid 3.1.12

squid-cache squid 3.1.0.6

squid-cache squid 3.1.0.5

squid-cache squid 3.1.0.14

squid-cache squid 3.1.0.13

squid-cache squid 3.0.stable8

squid-cache squid 3.0.stable7

squid-cache squid 3.0.stable23

squid-cache squid 3.0.stable22

squid-cache squid 3.0.stable16

squid-cache squid 3.0.stable15

squid-cache squid 3.0.stable1

squid-cache squid 3.0

squid-cache squid 4.0.3

squid-cache squid 4.0.2

squid-cache squid 3.5.0.2

squid-cache squid 3.5.0.1

squid-cache squid 3.5.4

squid-cache squid 3.5.5

squid-cache squid 3.4.3

squid-cache squid 3.4.2

squid-cache squid 3.4.0.2

squid-cache squid 3.4.0.1

squid-cache squid 3.3.2

squid-cache squid 3.3.13

squid-cache squid 3.3.0

squid-cache squid 3.2.9

squid-cache squid 3.2.2

squid-cache squid 3.2.13

squid-cache squid 3.2.0.6

squid-cache squid 3.2.0.5

squid-cache squid 3.2.0.16

squid-cache squid 3.2.0.15

squid-cache squid 3.1.9

squid-cache squid 3.1.8

squid-cache squid 3.1.15

squid-cache squid 3.1.14

squid-cache squid 3.1.0.8

squid-cache squid 3.1.0.7

squid-cache squid 3.1.0.17

squid-cache squid 3.1.0.16

squid-cache squid 3.1.0.15

squid-cache squid 3.1

squid-cache squid 3.0.stable9

squid-cache squid 3.0.stable25

squid-cache squid 3.0.stable24

squid-cache squid 3.0.stable17

squid-cache squid 3.0.stable11

squid-cache squid 3.0.stable10

squid-cache squid 4.0.6

squid-cache squid 4.0.7

squid-cache squid 3.5.9

squid-cache squid 3.5.1

squid-cache squid 3.5.11

squid-cache squid 3.5.12

squid-cache squid 3.5.8

squid-cache squid 3.4.9

squid-cache squid 3.4.11

squid-cache squid 3.4.10

squid-cache squid 3.3.7

squid-cache squid 3.3.6

squid-cache squid 3.3.5

squid-cache squid 3.3.10

squid-cache squid 3.3.1

squid-cache squid 3.2.6

squid-cache squid 3.2.5

squid-cache squid 3.2.1

squid-cache squid 3.2.0.9

squid-cache squid 3.2.0.2

squid-cache squid 3.2.0.19

squid-cache squid 3.2.0.12

squid-cache squid 3.2.0.11

squid-cache squid 3.1.5

squid-cache squid 3.1.4

squid-cache squid 3.1.11

squid-cache squid 3.1.10

squid-cache squid 3.1.0.4

squid-cache squid 3.1.0.3

squid-cache squid 3.1.0.12

squid-cache squid 3.1.0.11

squid-cache squid 3.0.stable6

squid-cache squid 3.0.stable5

squid-cache squid 3.0.stable21

squid-cache squid 3.0.stable20

squid-cache squid 3.0.stable14

squid-cache squid 3.0.stable13

squid-cache squid 4.0.5

squid-cache squid 4.0.4

squid-cache squid 3.5.0.4

squid-cache squid 3.5.0.3

squid-cache squid 3.5.13

squid-cache squid 3.5.14

squid-cache squid 3.5.3

squid-cache squid 3.4.8

squid-cache squid 3.4.4

squid-cache squid 3.4.1

squid-cache squid 3.4.0.3

squid-cache squid 3.3.4

squid-cache squid 3.3.3

squid-cache squid 3.3.0.3

squid-cache squid 3.3.0.2

squid-cache squid 3.2.4

squid-cache squid 3.2.3

squid-cache squid 3.2.0.8

squid-cache squid 3.2.0.7

squid-cache squid 3.2.0.18

squid-cache squid 3.2.0.17

squid-cache squid 3.2.0.10

squid-cache squid 3.2.0.1

squid-cache squid 3.1.3

squid-cache squid 3.1.2

squid-cache squid 3.1.1

squid-cache squid 3.1.0.9

squid-cache squid 3.1.0.2

squid-cache squid 3.1.0.18

squid-cache squid 3.1.0.10

squid-cache squid 3.1.0.1

squid-cache squid 3.0.stable4

squid-cache squid 3.0.stable3

squid-cache squid 3.0.stable2

squid-cache squid 3.0.stable19

squid-cache squid 3.0.stable18

squid-cache squid 3.0.stable12

Vendor Advisories

Debian Bug report logs - #819784 squid3: CVE-2016-3948 Package: src:squid3; Maintainer for src:squid3 is Luigi Gangitano <luigi@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 2 Apr 2016 09:09:05 UTC Severity: important Tags: patch, security, upstream Found in version squid3/3515-1 F ...
Debian Bug report logs - #819783 squid3: CVE-2016-3947 Package: src:squid3; Maintainer for src:squid3 is Luigi Gangitano <luigi@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 2 Apr 2016 09:09:01 UTC Severity: important Tags: patch, security, upstream Found in version squid3/3515-1 F ...
Several security issues were fixed in Squid ...
USN-3557-1 introduced a regression in Squid ...
An incorrect boundary check was found in the way squid handled the Vary header in HTTP responses, which could lead to an assertion failure A malicious HTTP server could use this flaw to crash squid using a specially crafted HTTP response ...