Arbitrary Code Execution Vulnerability in Squid ESI (CVE-2016-4054)
Arbitrary Code Execution Vulnerability in Squid ESI (CVE-2016-4054)
Release date:
Updated on:
Affected Systems:
Squid 4.x <4.0.9
Squid 3.x <3.5.17
Description:
CVE (CAN) ID: CVE-2016-4054
Squid is an efficient Web Cache and proxy program.
Squid 3.x <3.5.17, 4.x <4.0.9 has a buffer overflow vulnerability. By constructing an ESI response, remote attackers can execute arbitrary code.
<* Source: CESG
*>
Suggestion:
Vendor patch:
Squid
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.squid-cache.org/Advisories/SQUID-2016_6.txt
Configure Squid proxy http and rsync
Squid: high-speed Web Access
CentOS 6.2 compilation and installation Squid configuration Reverse Proxy Server
Simple configuration of Squid proxy and reverse proxy
Build high-availability Web servers using DNS + Squid + Nginx + MySQL in CentOS 6.4
Squid details: click here
Squid: click here
This article permanently updates the link address: