The Edge Side Includes (ESI) parser in Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not check buffer limits during XML parsing, which allows remote HTTP servers to cause a denial of service (assertion failure and daemon exit) via a crafted XML document, related to esi/CustomParser.cc and esi/CustomParser.h.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade squid | Aug 30, 2017 | Feb 27, 2016 |
| Freebsd | — | Upgrade squid | Dec 10, 2025 | Feb 24, 2016 |
| Gentoo Linux | — | Upgrade net-proxy/squid. | Oct 30, 2017 | Feb 27, 2016 |
| Huawei Euleros 2_0_sp1 | — | Upgrade squidUpgrade squid-migration-script | Nov 30, 2017 | Feb 27, 2016 |
| Oracle Solaris | — | Upgrade entire/ to version 11.4-11.4.0.0.1.15.0 on Solaris 11.4 | Oct 19, 2018 | Feb 27, 2016 |
| Oracle_linux | — | Upgrade squidUpgrade squid-migration-scriptUpgrade squid-sysvinit | Nov 9, 2016 | Feb 27, 2016 |
| Redhat_linux | — | Upgrade squid-migration-scriptUpgrade squid-debuginfoUpgrade squidUpgrade squid-sysvinitNo solution exists | Nov 4, 2016 | Feb 27, 2016 |
| Suse | — | Upgrade squidUpgrade squid3 | Aug 26, 2016 | Feb 27, 2016 |
| Ubuntu | — | Upgrade squid3 | Feb 6, 2018 | Feb 27, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub