Denial of service in Squid - CVE-2016-2571

 

Denial of service in Squid - CVE-2016-2571

Published: October 1, 2016 / Updated: February 6, 2018


Vulnerability identifier: #VU4172
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-2571
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause DoS condition on the target system.

The weakness exists in http.cc due to proceeding with the storage of certain data after a response-parsing failure. A remote attacker can use a specially crafted response, trigger assertion failure and daemon exit and cause the service to crash.

Affected software

Squid
Debian Linux
Ubuntu
squid (Alpine package)
squid (Ubuntu package)

How to mitigate CVE-2016-2571

Install update from vendor's website.

squid (Alpine package) - update to 3.4.14-r3
squid (Ubuntu package) - update to Ubuntu Pro (Infra-only)

External References

Related Security Bulletins