CVE-2016-2390
19.04.2016, 21:59
The FwdState::connectedToPeer method in FwdState.cc in Squid before 3.5.14 and 4.0.x before 4.0.6 does not properly handle SSL handshake errors when built with the --with-openssl option, which allows remote attackers to cause a denial of service (application crash) via a plaintext HTTP message.Enginsight
Vendor | Product | Version |
---|---|---|
squid-cache | squid | 𝑥 ≤ 3.5.13 |
squid-cache | squid | 4.0.4 |
squid-cache | squid | 4.0.5 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References