Buffer overflow in Squid - CVE-2016-4053

 

Buffer overflow in Squid - CVE-2016-4053

Published: April 25, 2016 / Updated: July 28, 2020


Vulnerability identifier: #VU32299
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-4053
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote attackers to obtain sensitive stack layout information via crafted Edge Side Includes (ESI) responses, related to incorrect use of assert and compiler optimization.


Affected software

Squid
squid (Alpine package)

How to mitigate CVE-2016-4053

Install update from vendor's website.

Squid - update to 3.5.17
squid (Alpine package) - update to 3.4.14-r1

External References

Related Security Bulletins