Buffer overflow in cachemgr.cgi in Squid 2.x, 3.x before 3.5.17, and 4.x before 4.0.9 might allow remote attackers to cause a denial of service or execute arbitrary code by seeding manager reports with crafted data.
CVSS Details
- CVSS 3.1 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade squid | Aug 30, 2017 | Apr 7, 2016 |
| Amazon_linux | — | Upgrade squid | Jun 15, 2016 | Apr 25, 2016 |
| Centos_linux | — | Upgrade squid34Upgrade squidUpgrade squid-sysvinit | May 31, 2016 | Apr 25, 2016 |
| Debian | — | Upgrade squidUpgrade squid3 | Jul 22, 2016 | Apr 25, 2016 |
| Freebsd | — | Upgrade squid | Dec 10, 2025 | Apr 21, 2016 |
| Gentoo Linux | — | Upgrade net-proxy/squid. | Oct 30, 2017 | Apr 25, 2016 |
| Huawei Euleros 2_0_sp1 | — | Upgrade squid | Nov 30, 2017 | Apr 25, 2016 |
| Oracle Solaris | — | Upgrade entire/ to version 11.4-11.4.0.0.1.15.0 on Solaris 11.4 | Oct 19, 2018 | Apr 25, 2016 |
| Oracle_linux | — | Upgrade squidUpgrade squid-sysvinitUpgrade squid34 | May 31, 2016 | Apr 25, 2016 |
| Redhat_linux | — | Upgrade squid-debuginfoUpgrade squid-sysvinitUpgrade squid34No solution existsUpgrade squidUpgrade squid34-debuginfo | Jun 1, 2016 | Apr 25, 2016 |
| Suse | — | Upgrade squid3Upgrade squid | Aug 26, 2016 | Apr 25, 2016 |
| Ubuntu | — | Upgrade squid-cgiUpgrade squid3 | Jun 9, 2016 | Apr 25, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub