CVE-2016-5408
published 2016-08-10CVE-2016-5408: Stack-based buffer overflow in the munge_other_line function in cachemgr.cgi in the squid package before 3.1.23-16.el6_8.6 in Red Hat Enterprise Linux 6 allows…
PriorityP357critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
4.35%
90.1th percentile
Stack-based buffer overflow in the munge_other_line function in cachemgr.cgi in the squid package before 3.1.23-16.el6_8.6 in Red Hat Enterprise Linux 6 allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-4051.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | linux | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5f9j-8ghm-9gxx: Stack-based buffer overflow in the munge_other_line function in cachemgr
ghsa_unreviewed·2022-05-13·CVSS 8.8
CVE-2016-5408 [HIGH] CWE-119 GHSA-5f9j-8ghm-9gxx: Stack-based buffer overflow in the munge_other_line function in cachemgr
Stack-based buffer overflow in the munge_other_line function in cachemgr.cgi in the squid package before 3.1.23-16.el6_8.6 in Red Hat Enterprise Linux 6 allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-4051.
Red Hat
squid: Buffer overflow vulnerability in cachemgr.cgi tool
vendor_redhat·2016-04-20·CVSS 8.8
CVE-2016-5408 [HIGH] CWE-122 squid: Buffer overflow vulnerability in cachemgr.cgi tool
squid: Buffer overflow vulnerability in cachemgr.cgi tool
Stack-based buffer overflow in the munge_other_line function in cachemgr.cgi in the squid package before 3.1.23-16.el6_8.6 in Red Hat Enterprise Linux 6 allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-4051.
It was found that the fix for CVE-2016-4051 released via RHSA-2016:1138 did not properly prevent the stack overflow in the munge_other_line() function. A remote attacker could send specially crafted data to the Squid proxy, which would exploit the cachemgr CGI utility, possibly triggering execution of arbitrary code.
Package: squid (Red Hat Enterprise Linux 5) - Not affected
Package: squid34 (Red Hat Enterprise Linux 6) - Not a
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-5408 squid: Buffer overflow vulnerability in cachemgr.cgi tool
bugzilla·2016-07-22·CVSS 8.8
CVE-2016-5408 [HIGH] CVE-2016-5408 squid: Buffer overflow vulnerability in cachemgr.cgi tool
CVE-2016-5408 squid: Buffer overflow vulnerability in cachemgr.cgi tool
Due to incorrect buffer management Squid cachemgr.cgi tool is vulnerable to a buffer overflow when processing remotely supplied inputs relayed to it from Squid.
This CVE is for an incomplete fix for CVE-2016-4051 as applied to squid packages in Red Hat Enterprise Linux 6, released via RHSA-2016:1138.
Upstream advisory for the original issue CVE-2016-4051:
http://www.squid-cache.org/Advisories/SQUID-2016_5.txt
Red Hat Enterprise Linux 6 erratum with the incomplete fix:
https://rhn.redhat.com/errata/RHSA-2016-1138.html
External Reference:
(none)
Discussion:
Acknowledgments:
Name: Amos Jeffries (Squid)
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2016:1573
Bugzilla
CVE-2016-4051 squid: buffer overflow in cachemgr.cgi
bugzilla·2016-04-21·CVSS 8.8
CVE-2016-4051 [HIGH] CVE-2016-4051 squid: buffer overflow in cachemgr.cgi
CVE-2016-4051 squid: buffer overflow in cachemgr.cgi
Due to incorrect buffer management Squid cachemgr.cgi tool is
vulnerable to a buffer overflow when processing remotely supplied
inputs relayed to it from Squid.
External references:
http://www.squid-cache.org/Advisories/SQUID-2016_5.txt
Upstream fixes:
[RHEL-7]
www.squid-cache.org/Versions/v3/3.3/changesets/SQUID-2016_5.patch
[Fedora-23]
http://www.squid-cache.org/Versions/v3/3.5/changesets/SQUID-2016_5.patch
[Fedora-22]
http://www.squid-cache.org/Versions/v3/3.4/changesets/SQUID-2016_5.patch
Discussion:
Created squid tracking bugs for this issue:
Affects: fedora-all [bug 1329144]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2016:1139 https://access.redhat.com/errata/RHSA-
2016-08-10
Published