Denial of service in Squid - CVE-2016-2569
Published: October 1, 2016 / Updated: February 6, 2018
Vulnerability identifier: #VU4170
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-2569
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists due to improper appending of data to String objects. A remote attacker can use a long string, as demonstrated by a crafted HTTP Vary header, trigger assertion failure and daemon exit and cause the service to crash.
The weakness exists due to improper appending of data to String objects. A remote attacker can use a long string, as demonstrated by a crafted HTTP Vary header, trigger assertion failure and daemon exit and cause the service to crash.
Affected software
Squid
squid (Alpine package)
squid (Ubuntu package)
Ubuntu
squid (Alpine package)
squid (Ubuntu package)
Ubuntu
How to mitigate CVE-2016-2569
Install update from vendor's website.
squid (Alpine package) - update to 3.4.14-r3
squid (Ubuntu package) - update to Ubuntu Pro (Infra-only)
squid (Ubuntu package) - update to Ubuntu Pro (Infra-only)