cbcvebase.
CVE-2016-4054
published 2016-04-25

CVE-2016-4054: Buffer overflow in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allows remote attackers to execute arbitrary code via crafted Edge Side Includes (ESI)…

PriorityP268high8.1CVSS 3.0
AVNACHPRNUINSUCHIHAH
EPSS
77.56%
99.5th percentile
Buffer overflow in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allows remote attackers to execute arbitrary code via crafted Edge Side Includes (ESI) responses.

Affected

147 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiansquid
oraclelinux
oraclelinux
squid-cachesquid
squid-cachesquid
squid-cachesquid
squid-cachesquid
squid-cachesquid
squid-cachesquid
squid-cachesquid
squid-cachesquid
squid-cachesquid
squid-cachesquid
squid-cachesquid
squid-cachesquid
squid-cachesquid
squid-cachesquid
squid-cachesquid
squid-cachesquid
squid-cachesquid
squid-cachesquid

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability is triggered via crafted ESI (Edge Side Includes) responses; monitor Squid reverse proxy or TLS/HTTPS interception deployments for anomalous ESI response content from upstream servers.
  • Attack vector requires attacker control of ESI components on an HTTP server; focus detection on ESI tags in HTTP responses passing through Squid configured as a reverse proxy or TLS/HTTPS interceptor.
  • Squid advisory SQUID-2016_6 is the authoritative upstream reference; use it to cross-reference patch status and confirm affected builds in your environment.
  • ·Exploitation requires Squid to be operating as a reverse proxy OR performing TLS/HTTPS interception; deployments in neither mode are not exposed to this attack path.
  • ·Red Hat Enterprise Linux 5 packages are explicitly marked Not Affected; patching priority should focus on RHEL 6, RHEL 7, and Fedora deployments running Squid 3.x < 3.5.17 or 4.x < 4.0.9.

CVSS provenance

nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.2HIGH
vendor_ubuntu8.2HIGH
vendor_debian8.1LOW
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.