CVE-2016-2569

HIGH

Squid - Improper Input Validation

Title source: rule

Description

Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not properly append data to String objects, which allows remote servers to cause a denial of service (assertion failure and daemon exit) via a long string, as demonstrated by a crafted HTTP Vary header.

Exploits (2)

nomisec WRITEUP 6 stars
by amit-raut · poc
https://github.com/amit-raut/CVE-2016-2569
gitlab WRITEUP
by amit-raut · poc
https://gitlab.com/amit-raut/CVE-2016-2569

Scores

CVSS v3 7.5
EPSS 0.7032
EPSS Percentile 98.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-20
Status published
Products (40)
squid-cache/squid 3.0 (9 CPE variants)
squid-cache/squid 3.0.stable1
squid-cache/squid 3.0.stable2
squid-cache/squid 3.0.stable3
squid-cache/squid 3.0.stable4
squid-cache/squid 3.0.stable5
squid-cache/squid 3.0.stable6
squid-cache/squid 3.0.stable7
squid-cache/squid 3.0.stable8
squid-cache/squid 3.0.stable9
... and 30 more
Published Feb 27, 2016
Tracked Since Feb 18, 2026