Memory corruption in Squid - CVE-2016-2570
Published: October 1, 2016 / Updated: February 6, 2018
Vulnerability identifier: #VU4171
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-2570
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists in the Edge Side Includes (ESI) parser due to improper checking of buffer limits during XML parsing. A remote attacker can use a specially crafted XML document, related to esi/CustomParser.cc and esi/CustomParser.h, as demonstrated by a crafted HTTP Vary header, trigger assertion failure and daemon exit and cause the service to crash.
The weakness exists in the Edge Side Includes (ESI) parser due to improper checking of buffer limits during XML parsing. A remote attacker can use a specially crafted XML document, related to esi/CustomParser.cc and esi/CustomParser.h, as demonstrated by a crafted HTTP Vary header, trigger assertion failure and daemon exit and cause the service to crash.
Affected software
Squid
squid (Alpine package)
squid (Ubuntu package)
Ubuntu
squid (Alpine package)
squid (Ubuntu package)
Ubuntu
How to mitigate CVE-2016-2570
Install update from vendor's website.
squid (Alpine package) - update to 3.4.14-r3
squid (Ubuntu package) - update to Ubuntu Pro (Infra-only)
squid (Ubuntu package) - update to Ubuntu Pro (Infra-only)