Denial of service in Squid - CVE-2016-2571
Published: October 1, 2016 / Updated: February 6, 2018
Vulnerability identifier: #VU4172
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-2571
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists in http.cc due to proceeding with the storage of certain data after a response-parsing failure. A remote attacker can use a specially crafted response, trigger assertion failure and daemon exit and cause the service to crash.
The weakness exists in http.cc due to proceeding with the storage of certain data after a response-parsing failure. A remote attacker can use a specially crafted response, trigger assertion failure and daemon exit and cause the service to crash.
Affected software
Squid
Debian Linux
Ubuntu
squid (Alpine package)
squid (Ubuntu package)
Debian Linux
Ubuntu
squid (Alpine package)
squid (Ubuntu package)
How to mitigate CVE-2016-2571
Install update from vendor's website.
squid (Alpine package) - update to 3.4.14-r3
squid (Ubuntu package) - update to Ubuntu Pro (Infra-only)
squid (Ubuntu package) - update to Ubuntu Pro (Infra-only)