CVE-2016-2570

Source
https://cve.org/CVERecord?id=CVE-2016-2570
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-2570.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2016-2570
Downstream
Related
Published
2016-02-27T05:59:04.797Z
Modified
2026-02-15T00:04:39.701246Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

The Edge Side Includes (ESI) parser in Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not check buffer limits during XML parsing, which allows remote HTTP servers to cause a denial of service (assertion failure and daemon exit) via a crafted XML document, related to esi/CustomParser.cc and esi/CustomParser.h.

References

Affected packages

Git / github.com/squid-cache/squid

Affected ranges

Type
GIT
Repo
https://github.com/squid-cache/squid
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

Other
HISTORIC_RELEASES
SQUID_3_0_PRE1
SQUID_3_0_PRE2
SQUID_3_0_PRE3
SQUID_3_0_PRE4
SQUID_3_0_PRE5
SQUID_3_0_PRE6
SQUID_3_0_PRE7
SQUID_3_0_RC1
SQUID_3_0_STABLE1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-2570.json"