CVE-2016-4053
CVE-2016-4053
Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote attackers to obtain sensitive stack layout information via crafted Edge Side Includes (ESI) responses, related to incorrect use of assert and compiler optimization.
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00040.htmlhttp://lists.opensuse.org/opensuse-updates/2016-08/msg00069.htmlhttps://access.redhat.com/errata/RHSA-2016:1138https://access.redhat.com/errata/RHSA-2016:1139https://access.redhat.com/errata/RHSA-2016:1140https://security.gentoo.org/glsa/201607-01http://www.debian.org/security/2016/dsa-3625http://www.openwall.com/lists/oss-security/2016/04/20/6http://www.openwall.com/lists/oss-security/2016/04/20/9http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html