Squid DoS Vulnerabilities (CVE-2016-3948)
Squid DoS Vulnerabilities (CVE-2016-3948)
Release date:
Updated on:
Affected Systems:
Squid Squid 〈 3.5.16
Squid Squid < 4.0.8
Description:
CVE (CAN) ID: CVE-2016-3948
Squid is an efficient Web Cache and proxy program.
In versions earlier than Squid 3.5.16 and earlier than 4.0.8, the boundary check is not correctly executed. By constructing an HTTP response, remote attackers can exploit this vulnerability to cause DOS.
<* Source: Santiago Ruano Rinc trade n
*>
Suggestion:
Vendor patch:
Squid
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.squid-cache.org/Versions/v3/3.2/changesets/squid-3.2-11839.patch
Http://www.squid-cache.org/Versions/v3/3.3/changesets/squid-3.3-12694.patch
Http://www.squid-cache.org/Versions/v3/3.1/changesets/squid-3.1-10495.patch
Http://www.squid-cache.org/Versions/v3/3.4/changesets/squid-3.4-13232.patch
Http://www.squid-cache.org/Versions/v3/3.5/changesets/squid-3.5-14015.patch
Http://www.squid-cache.org/Advisories/SQUID-2016_4.txt
Configure Squid proxy http and rsync
Squid: high-speed Web Access
CentOS 6.2 compilation and installation Squid configuration Reverse Proxy Server
Simple configuration of Squid proxy and reverse proxy
Build high-availability Web servers using DNS + Squid + Nginx + MySQL in CentOS 6.4
Squid details: click here
Squid: click here
This article permanently updates the link address: