ALT-PU-2014-1589-1
Closed vulnerabilities
Modified: 2024-11-21
CVE-2016-4051
Buffer overflow in cachemgr.cgi in Squid 2.x, 3.x before 3.5.17, and 4.x before 4.0.9 might allow remote attackers to cause a denial of service or execute arbitrary code by seeding manager reports with crafted data.
- SUSE-SU-2016:1996
- SUSE-SU-2016:1996
- SUSE-SU-2016:2089
- SUSE-SU-2016:2089
- openSUSE-SU-2016:2081
- openSUSE-SU-2016:2081
- DSA-3625
- DSA-3625
- [oss-security] 20160421 CVE Request: Squid HTTP Caching Proxy multiple issues
- [oss-security] 20160421 CVE Request: Squid HTTP Caching Proxy multiple issues
- [oss-security] 20160420 Re: CVE Request: Squid HTTP Caching Proxy multiple issues
- [oss-security] 20160420 Re: CVE Request: Squid HTTP Caching Proxy multiple issues
- http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html
- http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- 86788
- 86788
- 91787
- 91787
- 1035646
- 1035646
- http://www.squid-cache.org/Advisories/SQUID-2016_5.txt
- http://www.squid-cache.org/Advisories/SQUID-2016_5.txt
- USN-2995-1
- USN-2995-1
- RHSA-2016:1138
- RHSA-2016:1138
- RHSA-2016:1139
- RHSA-2016:1139
- RHSA-2016:1140
- RHSA-2016:1140
- GLSA-201607-01
- GLSA-201607-01
Modified: 2024-11-21
CVE-2016-4052
Multiple stack-based buffer overflows in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote HTTP servers to cause a denial of service or execute arbitrary code via crafted Edge Side Includes (ESI) responses.
- SUSE-SU-2016:1996
- SUSE-SU-2016:1996
- SUSE-SU-2016:2089
- SUSE-SU-2016:2089
- openSUSE-SU-2016:2081
- openSUSE-SU-2016:2081
- DSA-3625
- DSA-3625
- [oss-security] 20160421 CVE Request: Squid HTTP Caching Proxy multiple issues
- [oss-security] 20160421 CVE Request: Squid HTTP Caching Proxy multiple issues
- [oss-security] 20160420 Re: CVE Request: Squid HTTP Caching Proxy multiple issues
- [oss-security] 20160420 Re: CVE Request: Squid HTTP Caching Proxy multiple issues
- http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html
- http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- 86788
- 86788
- 91787
- 91787
- 1035647
- 1035647
- http://www.squid-cache.org/Advisories/SQUID-2016_6.txt
- http://www.squid-cache.org/Advisories/SQUID-2016_6.txt
- USN-2995-1
- USN-2995-1
- RHSA-2016:1138
- RHSA-2016:1138
- RHSA-2016:1139
- RHSA-2016:1139
- RHSA-2016:1140
- RHSA-2016:1140
- GLSA-201607-01
- GLSA-201607-01
Modified: 2024-11-21
CVE-2016-4053
Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote attackers to obtain sensitive stack layout information via crafted Edge Side Includes (ESI) responses, related to incorrect use of assert and compiler optimization.
- SUSE-SU-2016:1996
- SUSE-SU-2016:1996
- SUSE-SU-2016:2089
- SUSE-SU-2016:2089
- openSUSE-SU-2016:2081
- openSUSE-SU-2016:2081
- DSA-3625
- DSA-3625
- [oss-security] 20160421 CVE Request: Squid HTTP Caching Proxy multiple issues
- [oss-security] 20160421 CVE Request: Squid HTTP Caching Proxy multiple issues
- [oss-security] 20160420 Re: CVE Request: Squid HTTP Caching Proxy multiple issues
- [oss-security] 20160420 Re: CVE Request: Squid HTTP Caching Proxy multiple issues
- http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html
- http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- 86788
- 86788
- 91787
- 91787
- 1035647
- 1035647
- http://www.squid-cache.org/Advisories/SQUID-2016_6.txt
- http://www.squid-cache.org/Advisories/SQUID-2016_6.txt
- USN-2995-1
- USN-2995-1
- RHSA-2016:1138
- RHSA-2016:1138
- RHSA-2016:1139
- RHSA-2016:1139
- RHSA-2016:1140
- RHSA-2016:1140
- GLSA-201607-01
- GLSA-201607-01
Modified: 2024-11-21
CVE-2016-4054
Buffer overflow in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allows remote attackers to execute arbitrary code via crafted Edge Side Includes (ESI) responses.
- SUSE-SU-2016:1996
- SUSE-SU-2016:1996
- SUSE-SU-2016:2089
- SUSE-SU-2016:2089
- openSUSE-SU-2016:2081
- openSUSE-SU-2016:2081
- DSA-3625
- DSA-3625
- [oss-security] 20160421 CVE Request: Squid HTTP Caching Proxy multiple issues
- [oss-security] 20160421 CVE Request: Squid HTTP Caching Proxy multiple issues
- [oss-security] 20160420 Re: CVE Request: Squid HTTP Caching Proxy multiple issues
- [oss-security] 20160420 Re: CVE Request: Squid HTTP Caching Proxy multiple issues
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- 86788
- 86788
- 1035647
- 1035647
- http://www.squid-cache.org/Advisories/SQUID-2016_6.txt
- http://www.squid-cache.org/Advisories/SQUID-2016_6.txt
- USN-2995-1
- USN-2995-1
- RHSA-2016:1138
- RHSA-2016:1138
- RHSA-2016:1139
- RHSA-2016:1139
- RHSA-2016:1140
- RHSA-2016:1140
- GLSA-201607-01
- GLSA-201607-01
Modified: 2024-11-21
CVE-2016-4555
client_side_request.cc in Squid 3.x before 3.5.18 and 4.x before 4.0.10 allows remote servers to cause a denial of service (crash) via crafted Edge Side Includes (ESI) responses.
- http://bugs.squid-cache.org/show_bug.cgi?id=4455
- http://bugs.squid-cache.org/show_bug.cgi?id=4455
- SUSE-SU-2016:1996
- SUSE-SU-2016:1996
- SUSE-SU-2016:2089
- SUSE-SU-2016:2089
- openSUSE-SU-2016:2081
- openSUSE-SU-2016:2081
- DSA-3625
- DSA-3625
- [oss-security] 20160506 CVE Request: Squid HTTP caching proxy
- [oss-security] 20160506 CVE Request: Squid HTTP caching proxy
- [oss-security] 20160506 Re: CVE Request: Squid HTTP caching proxy
- [oss-security] 20160506 Re: CVE Request: Squid HTTP caching proxy
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- 1035770
- 1035770
- http://www.squid-cache.org/Advisories/SQUID-2016_9.txt
- http://www.squid-cache.org/Advisories/SQUID-2016_9.txt
- http://www.squid-cache.org/Versions/v3/3.4/changesets/SQUID-2016_9.patch
- http://www.squid-cache.org/Versions/v3/3.4/changesets/SQUID-2016_9.patch
- http://www.squid-cache.org/Versions/v3/3.5/changesets/SQUID-2016_9.patch
- http://www.squid-cache.org/Versions/v3/3.5/changesets/SQUID-2016_9.patch
- USN-2995-1
- USN-2995-1
- RHSA-2016:1139
- RHSA-2016:1139
- RHSA-2016:1140
- RHSA-2016:1140
- GLSA-201607-01
- GLSA-201607-01
Modified: 2024-11-21
CVE-2016-4556
Double free vulnerability in Esi.cc in Squid 3.x before 3.5.18 and 4.x before 4.0.10 allows remote servers to cause a denial of service (crash) via a crafted Edge Side Includes (ESI) response.
- SUSE-SU-2016:1996
- SUSE-SU-2016:1996
- SUSE-SU-2016:2089
- SUSE-SU-2016:2089
- openSUSE-SU-2016:2081
- openSUSE-SU-2016:2081
- DSA-3625
- DSA-3625
- [oss-security] 20160506 CVE Request: Squid HTTP caching proxy
- [oss-security] 20160506 CVE Request: Squid HTTP caching proxy
- [oss-security] 20160506 Re: CVE Request: Squid HTTP caching proxy
- [oss-security] 20160506 Re: CVE Request: Squid HTTP caching proxy
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- 1035770
- 1035770
- http://www.squid-cache.org/Advisories/SQUID-2016_9.txt
- http://www.squid-cache.org/Advisories/SQUID-2016_9.txt
- http://www.squid-cache.org/Versions/v3/3.4/changesets/SQUID-2016_9.patch
- http://www.squid-cache.org/Versions/v3/3.4/changesets/SQUID-2016_9.patch
- http://www.squid-cache.org/Versions/v3/3.5/changesets/SQUID-2016_9.patch
- http://www.squid-cache.org/Versions/v3/3.5/changesets/SQUID-2016_9.patch
- USN-2995-1
- USN-2995-1
- RHSA-2016:1138
- RHSA-2016:1138
- RHSA-2016:1139
- RHSA-2016:1139
- RHSA-2016:1140
- RHSA-2016:1140
- GLSA-201607-01
- GLSA-201607-01