Stack-based buffer overflow in the munge_other_line function in cachemgr.cgi in the squid package before 3.1.23-16.el6_8.6 in Red Hat Enterprise Linux 6 allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-4051.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux | — | Upgrade squid | Aug 22, 2016 | Aug 10, 2016 |
| Centos_linux | — | Upgrade squid | Aug 6, 2016 | Aug 4, 2016 |
| Debian | — | Upgrade squid3 | Mar 31, 2017 | Jul 22, 2016 |
| Oracle_linux | — | Upgrade squid | Aug 6, 2016 | Apr 20, 2016 |
| Redhat_linux | — | Upgrade squid-debuginfoUpgrade squid | Aug 6, 2016 | Aug 4, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub