CVE-2016-4556Improper Input Validation in Squid

Severity
7.5HIGHNVD
EPSS
56.9%
top 1.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 10
Latest updateMay 13

Description

Double free vulnerability in Esi.cc in Squid 3.x before 3.5.18 and 4.x before 4.0.10 allows remote servers to cause a denial of service (crash) via a crafted Edge Side Includes (ESI) response.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDsquid-cache/squid142 versions+141
NVDoracle/linux6, 7+1

Also affects: Ubuntu Linux 12.04, 14.04, 15.10, 16.04

Patches

🔴Vulnerability Details

3
GHSA
GHSA-2xhq-835p-4pg5: Double free vulnerability in Esi2022-05-13
OSV
CVE-2016-4556: Double free vulnerability in Esi2016-05-10
CVEList
CVE-2016-4556: Double free vulnerability in Esi2016-05-10

📋Vendor Advisories

3
Ubuntu
Squid vulnerabilities2016-06-09
Red Hat
squid: SIGSEGV in ESIContext response handling2016-05-06
Debian
CVE-2016-4556: squid - Double free vulnerability in Esi.cc in Squid 3.x before 3.5.18 and 4.x before 4....2016

💬Community

4
Bugzilla
CVE-2016-4556 squid: SIGSEGV in ESIContext response handling2016-05-10
Bugzilla
CVE-2016-4556 squid: SegFault from ESIInclude::Start [fedora-all]2016-05-10
Bugzilla
CVE-2016-4553 CVE-2016-4554 CVE-2016-4555 CVE-2016-4556 squid: various flaws [fedora-all]2016-05-09
Bugzilla
CVE-2016-4555 squid: SegFault from ESIInclude::Start2016-05-09
CVE-2016-4556 — Improper Input Validation in Squid | cvebase