VulnerabilityModified
CVE-2016-4051
Buffer overflow in cachemgr.cgi in Squid 2.x, 3.x before 3.5.17, and 4.x before 4.0.9 might allow remote attackers to cause a denial of service or execute arbitrary code by seeding manager reports with crafted data.
HIGH 8.8EPSS 18.3%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 18.3%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
Buffer overflow in cachemgr.cgi in Squid 2.x, 3.x before 3.5.17, and 4.x before 4.0.9 might allow remote attackers to cause a denial of service or execute arbitrary code by seeding manager reports with crafted data.
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 18.28% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- canonical/ubuntu linux · oracle/linux · squid-cache/squid
- Source
- cve@mitre.org
References
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00040.html
- http://lists.opensuse.org/opensuse-updates/2016-08/msg00069.html
- http://www.debian.org/security/2016/dsa-3625
- http://www.openwall.com/lists/oss-security/2016/04/20/6Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2016/04/20/9Mailing List, Third Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlPatch, Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlThird Party Advisory
- http://www.securityfocus.com/bid/86788
- http://www.securityfocus.com/bid/91787Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1035646Third Party Advisory, VDB Entry
- http://www.squid-cache.org/Advisories/SQUID-2016_5.txtVendor Advisory
- http://www.ubuntu.com/usn/USN-2995-1Third Party Advisory
- https://access.redhat.com/errata/RHSA-2016:1138
- https://access.redhat.com/errata/RHSA-2016:1139
- https://access.redhat.com/errata/RHSA-2016:1140
- https://security.gentoo.org/glsa/201607-01
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00040.html
- http://lists.opensuse.org/opensuse-updates/2016-08/msg00069.html
- http://www.debian.org/security/2016/dsa-3625
- http://www.openwall.com/lists/oss-security/2016/04/20/6Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2016/04/20/9Mailing List, Third Party Advisory
- http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlPatch, Third Party Advisory
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlThird Party Advisory
- http://www.securityfocus.com/bid/86788
- http://www.securityfocus.com/bid/91787Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1035646Third Party Advisory, VDB Entry
- http://www.squid-cache.org/Advisories/SQUID-2016_5.txtVendor Advisory
- http://www.ubuntu.com/usn/USN-2995-1Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.