Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not properly append data to String objects, which allows remote servers to cause a denial of service (assertion failure and daemon exit) via a long string, as demonstrated by a crafted HTTP Vary header.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade squid | Aug 30, 2017 | Feb 27, 2016 |
| Freebsd | — | Upgrade squid | Dec 10, 2025 | Feb 24, 2016 |
| Gentoo Linux | — | Upgrade net-proxy/squid. | Oct 30, 2017 | Feb 27, 2016 |
| Huawei Euleros 2_0_sp1 | — | Upgrade squid-migration-scriptUpgrade squid | Nov 30, 2017 | Feb 27, 2016 |
| Oracle Solaris | — | Upgrade entire/ to version 11.4-11.4.0.0.1.15.0 on Solaris 11.4 | Oct 19, 2018 | Feb 27, 2016 |
| Oracle_linux | — | Upgrade squid-migration-scriptUpgrade squidUpgrade squid-sysvinit | Nov 9, 2016 | Feb 27, 2016 |
| Redhat_linux | — | Upgrade squidUpgrade squid-sysvinitNo solution existsUpgrade squid-migration-scriptUpgrade squid-debuginfo | Nov 4, 2016 | Feb 27, 2016 |
| Suse | — | Upgrade squid3Upgrade squid | Aug 26, 2016 | Feb 27, 2016 |
| Ubuntu | — | Upgrade squid3 | Feb 6, 2018 | Feb 27, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub