CVE-2016-2571 PUBLISHED

http.cc in Squid 3.x before 3.5.15 and 4.x before 4.0.7 proceeds with the storage of certain data after a response-parsing failure, which allows remote HTTP servers to cause a denial of service (assertion failure and daemon exit) via a malformed response.

EPSS 14.33% · 94.3th percentile

Risk Scores

EPSS Score
14.33%
94.3th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSsquid33.5.12-1ubuntu7.4, 0, 3.3.8-1ubuntu16
Ubuntu:14.04:LTSsquid30, 3.3.8-1ubuntu3, 3.3.8-1ubuntu4

Timeline

References

Open in Interactive Console →