ALT-PU-2016-1444-1
Closed vulnerabilities
Modified: 2024-11-21
CVE-2016-3947
Heap-based buffer overflow in the Icmp6::Recv function in icmp/Icmp6.cc in the pinger utility in Squid before 3.5.16 and 4.x before 4.0.8 allows remote servers to cause a denial of service (performance degradation or transition failures) or write sensitive information to log files via an ICMPv6 packet.
- SUSE-SU-2016:1996
- SUSE-SU-2016:1996
- SUSE-SU-2016:2089
- SUSE-SU-2016:2089
- openSUSE-SU-2016:2081
- openSUSE-SU-2016:2081
- 1035457
- 1035457
- http://www.squid-cache.org/Advisories/SQUID-2016_3.txt
- http://www.squid-cache.org/Advisories/SQUID-2016_3.txt
- http://www.squid-cache.org/Versions/v3/3.1/changesets/squid-3.1-10495.patch
- http://www.squid-cache.org/Versions/v3/3.1/changesets/squid-3.1-10495.patch
- http://www.squid-cache.org/Versions/v3/3.2/changesets/squid-3.2-11839.patch
- http://www.squid-cache.org/Versions/v3/3.2/changesets/squid-3.2-11839.patch
- http://www.squid-cache.org/Versions/v3/3.3/changesets/squid-3.3-12694.patch
- http://www.squid-cache.org/Versions/v3/3.3/changesets/squid-3.3-12694.patch
- http://www.squid-cache.org/Versions/v3/3.4/changesets/squid-3.4-13232.patch
- http://www.squid-cache.org/Versions/v3/3.4/changesets/squid-3.4-13232.patch
- http://www.squid-cache.org/Versions/v3/3.5/changesets/squid-3.5-14015.patch
- http://www.squid-cache.org/Versions/v3/3.5/changesets/squid-3.5-14015.patch
- USN-2995-1
- USN-2995-1
- GLSA-201607-01
- GLSA-201607-01
Modified: 2024-11-21
CVE-2016-3948
Squid 3.x before 3.5.16 and 4.x before 4.0.8 improperly perform bounds checking, which allows remote attackers to cause a denial of service via a crafted HTTP response, related to Vary headers.
- SUSE-SU-2016:1996
- SUSE-SU-2016:1996
- SUSE-SU-2016:2089
- SUSE-SU-2016:2089
- openSUSE-SU-2016:2081
- openSUSE-SU-2016:2081
- RHSA-2016:2600
- RHSA-2016:2600
- 1035458
- 1035458
- http://www.squid-cache.org/Advisories/SQUID-2016_4.txt
- http://www.squid-cache.org/Advisories/SQUID-2016_4.txt
- http://www.squid-cache.org/Versions/v3/3.5/changesets/squid-3.5-14016.patch
- http://www.squid-cache.org/Versions/v3/3.5/changesets/squid-3.5-14016.patch
- GLSA-201607-01
- GLSA-201607-01
- USN-3557-1
- USN-3557-1
Modified: 2024-11-21
CVE-2016-4051
Buffer overflow in cachemgr.cgi in Squid 2.x, 3.x before 3.5.17, and 4.x before 4.0.9 might allow remote attackers to cause a denial of service or execute arbitrary code by seeding manager reports with crafted data.
- SUSE-SU-2016:1996
- SUSE-SU-2016:1996
- SUSE-SU-2016:2089
- SUSE-SU-2016:2089
- openSUSE-SU-2016:2081
- openSUSE-SU-2016:2081
- DSA-3625
- DSA-3625
- [oss-security] 20160421 CVE Request: Squid HTTP Caching Proxy multiple issues
- [oss-security] 20160421 CVE Request: Squid HTTP Caching Proxy multiple issues
- [oss-security] 20160420 Re: CVE Request: Squid HTTP Caching Proxy multiple issues
- [oss-security] 20160420 Re: CVE Request: Squid HTTP Caching Proxy multiple issues
- http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html
- http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- 86788
- 86788
- 91787
- 91787
- 1035646
- 1035646
- http://www.squid-cache.org/Advisories/SQUID-2016_5.txt
- http://www.squid-cache.org/Advisories/SQUID-2016_5.txt
- USN-2995-1
- USN-2995-1
- RHSA-2016:1138
- RHSA-2016:1138
- RHSA-2016:1139
- RHSA-2016:1139
- RHSA-2016:1140
- RHSA-2016:1140
- GLSA-201607-01
- GLSA-201607-01
Modified: 2024-11-21
CVE-2016-4052
Multiple stack-based buffer overflows in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote HTTP servers to cause a denial of service or execute arbitrary code via crafted Edge Side Includes (ESI) responses.
- SUSE-SU-2016:1996
- SUSE-SU-2016:1996
- SUSE-SU-2016:2089
- SUSE-SU-2016:2089
- openSUSE-SU-2016:2081
- openSUSE-SU-2016:2081
- DSA-3625
- DSA-3625
- [oss-security] 20160421 CVE Request: Squid HTTP Caching Proxy multiple issues
- [oss-security] 20160421 CVE Request: Squid HTTP Caching Proxy multiple issues
- [oss-security] 20160420 Re: CVE Request: Squid HTTP Caching Proxy multiple issues
- [oss-security] 20160420 Re: CVE Request: Squid HTTP Caching Proxy multiple issues
- http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html
- http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- 86788
- 86788
- 91787
- 91787
- 1035647
- 1035647
- http://www.squid-cache.org/Advisories/SQUID-2016_6.txt
- http://www.squid-cache.org/Advisories/SQUID-2016_6.txt
- USN-2995-1
- USN-2995-1
- RHSA-2016:1138
- RHSA-2016:1138
- RHSA-2016:1139
- RHSA-2016:1139
- RHSA-2016:1140
- RHSA-2016:1140
- GLSA-201607-01
- GLSA-201607-01
Modified: 2024-11-21
CVE-2016-4053
Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote attackers to obtain sensitive stack layout information via crafted Edge Side Includes (ESI) responses, related to incorrect use of assert and compiler optimization.
- SUSE-SU-2016:1996
- SUSE-SU-2016:1996
- SUSE-SU-2016:2089
- SUSE-SU-2016:2089
- openSUSE-SU-2016:2081
- openSUSE-SU-2016:2081
- DSA-3625
- DSA-3625
- [oss-security] 20160421 CVE Request: Squid HTTP Caching Proxy multiple issues
- [oss-security] 20160421 CVE Request: Squid HTTP Caching Proxy multiple issues
- [oss-security] 20160420 Re: CVE Request: Squid HTTP Caching Proxy multiple issues
- [oss-security] 20160420 Re: CVE Request: Squid HTTP Caching Proxy multiple issues
- http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html
- http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- 86788
- 86788
- 91787
- 91787
- 1035647
- 1035647
- http://www.squid-cache.org/Advisories/SQUID-2016_6.txt
- http://www.squid-cache.org/Advisories/SQUID-2016_6.txt
- USN-2995-1
- USN-2995-1
- RHSA-2016:1138
- RHSA-2016:1138
- RHSA-2016:1139
- RHSA-2016:1139
- RHSA-2016:1140
- RHSA-2016:1140
- GLSA-201607-01
- GLSA-201607-01
Modified: 2024-11-21
CVE-2016-4054
Buffer overflow in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allows remote attackers to execute arbitrary code via crafted Edge Side Includes (ESI) responses.
- SUSE-SU-2016:1996
- SUSE-SU-2016:1996
- SUSE-SU-2016:2089
- SUSE-SU-2016:2089
- openSUSE-SU-2016:2081
- openSUSE-SU-2016:2081
- DSA-3625
- DSA-3625
- [oss-security] 20160421 CVE Request: Squid HTTP Caching Proxy multiple issues
- [oss-security] 20160421 CVE Request: Squid HTTP Caching Proxy multiple issues
- [oss-security] 20160420 Re: CVE Request: Squid HTTP Caching Proxy multiple issues
- [oss-security] 20160420 Re: CVE Request: Squid HTTP Caching Proxy multiple issues
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
- 86788
- 86788
- 1035647
- 1035647
- http://www.squid-cache.org/Advisories/SQUID-2016_6.txt
- http://www.squid-cache.org/Advisories/SQUID-2016_6.txt
- USN-2995-1
- USN-2995-1
- RHSA-2016:1138
- RHSA-2016:1138
- RHSA-2016:1139
- RHSA-2016:1139
- RHSA-2016:1140
- RHSA-2016:1140
- GLSA-201607-01
- GLSA-201607-01