|
|
Log in / Subscribe / Register

squid: denial of service

Package(s):squid3 CVE #(s):CVE-2016-2569 CVE-2016-2571
Created:March 1, 2016 Updated:November 11, 2016
Description: From the CVE entries:

CVE-2016-2569: Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not properly append data to String objects, which allows remote servers to cause a denial of service (assertion failure and daemon exit) via a long string, as demonstrated by a crafted HTTP Vary header.

CVE-2016-2571: http.cc in Squid 3.x before 3.5.15 and 4.x before 4.0.7 proceeds with the storage of certain data after a response-parsing failure, which allows remote HTTP servers to cause a denial of service (assertion failure and daemon exit) via a malformed response.

Alerts:
Oracle ELSA-2016-2600 squid 2016-11-10
Red Hat RHSA-2016:2600-02 squid 2016-11-03
SUSE SUSE-SU-2016:2089-1 squid3 2016-08-16
openSUSE openSUSE-SU-2016:2081-1 squid 2016-08-16
SUSE SUSE-SU-2016:1996-1 squid3 2016-08-09
Fedora FEDORA-2016-b3b9407940 squid 2016-07-13
Gentoo 201607-01 squid 2016-07-09
Fedora FEDORA-2016-7b40eb9e29 squid 2016-05-06
Fedora FEDORA-2016-7b40eb9e29 libecap 2016-05-06
Scientific Linux SLSA-2016:2600-2 squid 2016-12-14
Debian DSA-3522-1 squid3 2016-03-20
Ubuntu USN-2921-1 squid3 2016-03-07
Mageia MGASA-2016-0095 squid 2016-03-07
Debian-LTS DLA-445-2 squid3 2016-03-03
Debian-LTS DLA-445-1 squid3 2016-02-29

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds