Memory corruption in Squid - CVE-2016-3948
Published: October 1, 2016 / Updated: February 6, 2018
Vulnerability identifier: #VU4175
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-3948
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists due to improper bounds checking. A remote attacker can use a specially crafted HTTP response, related to Vary headers, trigger memory corruption and cause the service to crash.
The weakness exists due to improper bounds checking. A remote attacker can use a specially crafted HTTP response, related to Vary headers, trigger memory corruption and cause the service to crash.
Affected software
Squid
Ubuntu
Fedora
squid (Ubuntu package)
squid
Ubuntu
Fedora
squid (Ubuntu package)
squid
How to mitigate CVE-2016-3948
Install update from vendor's website.
squid (Ubuntu package) - update to Ubuntu Pro (Infra-only)
squid - addressed in versions 3.5.10-2.fc22, 3.5.16-1.fc24
squid - addressed in versions 3.5.10-2.fc22, 3.5.16-1.fc24