7.5
CVSSv3

CVE-2016-4556

Published: 10/05/2016 Updated: 27/12/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Double free vulnerability in Esi.cc in Squid 3.x prior to 3.5.18 and 4.x prior to 4.0.10 allows remote servers to cause a denial of service (crash) via a crafted Edge Side Includes (ESI) response.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

squid-cache squid 3.5.15

squid-cache squid 3.5.14

squid-cache squid 3.5.7

squid-cache squid 3.5.6

squid-cache squid 3.5.0.3

squid-cache squid 3.5.0.2

squid-cache squid 3.4.13

squid-cache squid 3.4.12

squid-cache squid 3.4.0.2

squid-cache squid 3.4.0.1

squid-cache squid 3.3.4

squid-cache squid 3.3.3

squid-cache squid 3.3.2

squid-cache squid 3.3.0.3

squid-cache squid 3.3.0.2

squid-cache squid 3.2.4

squid-cache squid 3.2.3

squid-cache squid 3.2.0.9

squid-cache squid 3.2.0.8

squid-cache squid 3.2.0.7

squid-cache squid 3.2.0.18

squid-cache squid 3.2.0.17

squid-cache squid 3.2.0.10

squid-cache squid 3.2.0.1

squid-cache squid 3.1.9

squid-cache squid 3.1.8

squid-cache squid 3.1.2

squid-cache squid 3.1.15

squid-cache squid 3.1.12.3

squid-cache squid 3.1.12.2

squid-cache squid 3.1.0.3

squid-cache squid 3.1.0.2

squid-cache squid 3.1.0.12

squid-cache squid 3.1.0.11

squid-cache squid 3.5.11

squid-cache squid 3.5.10

squid-cache squid 3.5.3

squid-cache squid 3.5.2

squid-cache squid 3.4.8

squid-cache squid 3.4.4

squid-cache squid 3.4.1

squid-cache squid 3.4.4.2

squid-cache squid 3.3.8

squid-cache squid 3.3.7

squid-cache squid 3.3.11

squid-cache squid 3.3.10

squid-cache squid 3.2.8

squid-cache squid 3.2.7

squid-cache squid 3.2.12

squid-cache squid 3.2.11

squid-cache squid 3.2.0.4

squid-cache squid 3.2.0.3

squid-cache squid 3.2.0.14

squid-cache squid 3.2.0.13

squid-cache squid 3.1.20

squid-cache squid 3.1.19

squid-cache squid 3.1.5.1

squid-cache squid 3.1.5

squid-cache squid 3.1.12

squid-cache squid 3.1.11

squid-cache squid 3.1.0.8

squid-cache squid 3.1.0.7

squid-cache squid 3.1.0.6

squid-cache squid 3.1.0.16

squid-cache squid 3.1.0.15

squid-cache squid 3.1

squid-cache squid 3.0

squid-cache squid 3.5.17

squid-cache squid 3.5.16

squid-cache squid 3.5.9

squid-cache squid 3.5.8

squid-cache squid 3.5.1

squid-cache squid 3.5.0.4

squid-cache squid 3.4.3

squid-cache squid 3.4.2

squid-cache squid 3.4.4.1

squid-cache squid 3.4.0.3

squid-cache squid 3.3.6

squid-cache squid 3.3.5

squid-cache squid 3.3.1

squid-cache squid 3.3.0.1

squid-cache squid 3.2.6

squid-cache squid 3.2.5

squid-cache squid 3.2.10

squid-cache squid 3.2.1

squid-cache squid 3.2.0.2

squid-cache squid 3.2.0.19

squid-cache squid 3.2.0.12

squid-cache squid 3.2.0.11

squid-cache squid 3.1.18

squid-cache squid 3.1.17

squid-cache squid 3.1.16

squid-cache squid 3.1.4

squid-cache squid 3.1.3

squid-cache squid 3.1.10

squid-cache squid 3.1.1

squid-cache squid 3.1.0.5

squid-cache squid 3.1.0.4

squid-cache squid 3.1.0.14

squid-cache squid 3.1.0.13

squid-cache squid 3.5.13

squid-cache squid 3.5.12

squid-cache squid 3.5.5

squid-cache squid 3.5.4

squid-cache squid 3.5.0.1

squid-cache squid 3.4.14

squid-cache squid 3.4.9

squid-cache squid 3.4.11

squid-cache squid 3.4.10

squid-cache squid 3.3.14

squid-cache squid 3.3.9

squid-cache squid 3.3.13

squid-cache squid 3.3.12

squid-cache squid 3.3.0

squid-cache squid 3.2.9

squid-cache squid 3.2.2

squid-cache squid 3.2.13

squid-cache squid 3.2.0.6

squid-cache squid 3.2.0.5

squid-cache squid 3.2.0.16

squid-cache squid 3.2.0.15

squid-cache squid 3.1.22

squid-cache squid 3.1.21

squid-cache squid 3.1.7

squid-cache squid 3.1.6

squid-cache squid 3.1.14

squid-cache squid 3.1.13

squid-cache squid 3.1.12.1

squid-cache squid 3.1.0.9

squid-cache squid 3.1.0.18

squid-cache squid 3.1.0.17

squid-cache squid 3.1.0.10

squid-cache squid 3.1.0.1

squid-cache squid 4.0.8

squid-cache squid 4.0.7

squid-cache squid 4.0.3

squid-cache squid 4.0.2

squid-cache squid 4.0.9

squid-cache squid 4.0.1

squid-cache squid 4.0.6

squid-cache squid 4.0.5

squid-cache squid 4.0.4

oracle linux 7

oracle linux 6

canonical ubuntu linux 15.10

canonical ubuntu linux 14.04

canonical ubuntu linux 12.04

canonical ubuntu linux 16.04

Vendor Advisories

Debian Bug report logs - #823968 squid3: CVE-2016-4553 CVE-2016-4554 CVE-2016-4555 CVE-2016-4556 Package: src:squid3; Maintainer for src:squid3 is Luigi Gangitano <luigi@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 10 May 2016 20:12:01 UTC Severity: important Tags: fixed-upstream, sec ...
Several security issues were fixed in Squid ...
Several security issues have been discovered in the Squid caching proxy CVE-2016-4051: CESG and Yuriy M Kaminskiy discovered that Squid cachemgrcgi was vulnerable to a buffer overflow when processing remotely supplied inputs relayed through Squid CVE-2016-4052: CESG discovered that a buffer overflow made Squid vulnerable to a ...
A buffer overflow flaw was found in the way the Squid cachemgrcgi utility processed remotely relayed Squid input When the CGI interface utility is used, a remote attacker could possibly use this flaw to execute arbitrary code (CVE-2016-4051) Buffer overflow and input validation flaws were found in the way Squid processed ESI responses If Squid ...
An incorrect reference counting flaw was found in the way Squid processes ESI responses If Squid is configured as reverse-proxy, for for TLS/HTTPS interception, an attacker controlling a server accessed by Squid, could crash the squid worker, causing a Denial of Service attack ...