Wind River Support Network

HomeDefectsLIN8-3009
Fixed

LIN8-3009 : Security Advisory - squid - CVE-2016-2570

Created: Mar 14, 2016    Updated: Dec 3, 2018
Resolved Date: Apr 10, 2016
Found In Version: 8.0
Fix Version: 8.0.0.5
Severity: Standard
Applicable for: Wind River Linux 8
Component/s: Userspace

Description

The Edge Side Includes (ESI) parser in Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not check buffer limits during XML parsing, which allows remote HTTP servers to cause a denial of service (assertion failure and daemon exit) via a crafted XML document, related to esi/CustomParser.cc and esi/CustomParser.h.

http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-2570

Other Downloads


CVEs


Live chat
Online