CVE-2016-2569
HIGHSquid - Improper Input Validation
Title source: ruleDescription
Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not properly append data to String objects, which allows remote servers to cause a denial of service (assertion failure and daemon exit) via a long string, as demonstrated by a crafted HTTP Vary header.
Exploits (2)
References (11)
Scores
CVSS v3
7.5
EPSS
0.7032
EPSS Percentile
98.7%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-20
Status
published
Products (40)
squid-cache/squid
3.0 (9 CPE variants)
squid-cache/squid
3.0.stable1
squid-cache/squid
3.0.stable2
squid-cache/squid
3.0.stable3
squid-cache/squid
3.0.stable4
squid-cache/squid
3.0.stable5
squid-cache/squid
3.0.stable6
squid-cache/squid
3.0.stable7
squid-cache/squid
3.0.stable8
squid-cache/squid
3.0.stable9
... and 30 more
Published
Feb 27, 2016
Tracked Since
Feb 18, 2026