cbcvebase.
CVE-2016-4556
published 2016-05-10

CVE-2016-4556: Double free vulnerability in Esi.cc in Squid 3.x before 3.5.18 and 4.x before 4.0.10 allows remote servers to cause a denial of service (crash) via a crafted…

PriorityP344high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
23.11%
97.5th percentile
Double free vulnerability in Esi.cc in Squid 3.x before 3.5.18 and 4.x before 4.0.10 allows remote servers to cause a denial of service (crash) via a crafted Edge Side Includes (ESI) response.

Affected

149 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiansquid
oraclelinux
oraclelinux
squid-cachesquid
squid-cachesquid
squid-cachesquid
squid-cachesquid
squid-cachesquid
squid-cachesquid
squid-cachesquid
squid-cachesquid
squid-cachesquid
squid-cachesquid
squid-cachesquid
squid-cachesquid
squid-cachesquid
squid-cachesquid
squid-cachesquid
squid-cachesquid
squid-cachesquid
squid-cachesquid

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability is triggered via a crafted ESI (Edge Side Includes) response from a remote server; monitor Squid worker crashes (SIGSEGV/segfault) originating from ESIContext or ESIInclude::Start processing
  • Exploitation requires Squid to be configured as a reverse-proxy or with TLS/HTTPS interception enabled; scope the detection to those deployment modes
  • Look for repeated or unexpected Squid worker process restarts (crash loop) as an indicator of active exploitation of this double-free in ESI response handling
  • ·Only Squid versions 3.x before 3.5.18 and 4.x before 4.0.10 are affected; instances running patched versions are not vulnerable
  • ·Red Hat Enterprise Linux 5 is listed as not affected; focus detection efforts on RHEL 6/7 and Fedora deployments running vulnerable Squid builds
  • ·Upstream patches are available for Squid 3.5 and 3.4 branches via the SQUID-2016_9 advisory; verify patch application before deprioritising detection

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv8.2HIGH
vendor_ubuntu8.2HIGH
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.