SB2016050939 - Buffer overflow in squid (Alpine package)
Published: May 9, 2016
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Buffer overflow (CVE-ID: CVE-2016-4054)
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
Buffer overflow in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allows remote attackers to execute arbitrary code via crafted Edge Side Includes (ESI) responses.
Remediation
Install update from vendor's website.