CVE-2016-2569
HIGHSquid 3.x < 3.5.15 and 4.x < 4.0.7 - Denial of Service via HTTP Vary Header
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2016-2569. PoCs published by amit-raut.
AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2016-2569, a denial-of-service vulnerability in Squid proxy due to improper handling of long strings in String objects. It includes patch analysis, exploitation setup, and a Python script to test the vulnerability.
Description
Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not properly append data to String objects, which allows remote servers to cause a denial of service (assertion failure and daemon exit) via a long string, as demonstrated by a crafted HTTP Vary header.
Exploits (2)
This repository provides a detailed technical analysis of CVE-2016-2569, a denial-of-service vulnerability in Squid proxy due to improper handling of long strings in String objects. It includes patch analysis, exploitation setup, and a Python script to test the vulnerability.
This repository provides a detailed technical analysis of CVE-2016-2569, a denial-of-service vulnerability in Squid Caching Proxy. It includes patch analysis, vulnerability root cause, and a step-by-step exploitation guide using a crafted HTTP Vary header.
References (11)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H