VDB
BDU%3A2016-00733
BDU%3A2016-00733
PUBLISHED
CVSS 5 MEDIUM
Уязвимость прокси-сервера Squid, позволяющая нарушителю вызвать отказ в обслуживании
Risk Scores
CVSS 2.0
5
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Squid Software Foundation | Squid |
Exploit Intelligence
- Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not properly append data to String objects, which allows remote servers to cause a denial of service (assertion failure and daemon exit) via a long string, as demonstrated by a crafted HTTP Vary header. (github-poc-repo)
- Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not properly append data to String objects, which allows remote servers to cause a denial of service (assertion failure and daemon exit) via a long string, as demonstrated by a crafted HTTP Vary header. (github-poc)
Timeline
- Mar 31, 2016 CVE Published
- Mar 23, 2021 CVE Updated