Multiple stack-based buffer overflows in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote HTTP servers to cause a denial of service or execute arbitrary code via crafted Edge Side Includes (ESI) responses.
{
"unresolved_ranges": [
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "3.0"
}
],
"cpe": "cpe:2.3:a:squid-cache:squid:3.0:*:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "3.3.0"
}
],
"cpe": "cpe:2.3:a:squid-cache:squid:3.3.0:*:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "12.04"
}
],
"cpe": "cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "14.04"
}
],
"cpe": "cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "15.10"
}
],
"cpe": "cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "16.04"
}
],
"cpe": "cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*"
}
]
}{
"source": "CPE_FIELD",
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "3.1"
},
{
"last_affected": "3.1.0.1"
},
{
"last_affected": "3.1.0.2"
},
{
"last_affected": "3.1.0.3"
},
{
"last_affected": "3.1.0.4"
},
{
"last_affected": "3.1.0.5"
},
{
"last_affected": "3.1.0.6"
},
{
"last_affected": "3.1.0.7"
},
{
"last_affected": "3.1.0.8"
},
{
"last_affected": "3.1.0.9"
},
{
"last_affected": "3.1.0.10"
},
{
"last_affected": "3.1.0.11"
},
{
"last_affected": "3.1.0.12"
},
{
"last_affected": "3.1.0.13"
},
{
"last_affected": "3.1.0.14"
},
{
"last_affected": "3.1.0.15"
},
{
"last_affected": "3.1.0.16"
},
{
"last_affected": "3.1.0.17"
},
{
"last_affected": "3.1.0.18"
},
{
"last_affected": "3.1.1"
},
{
"last_affected": "3.1.2"
},
{
"last_affected": "3.1.3"
},
{
"last_affected": "3.1.4"
},
{
"last_affected": "3.1.5"
},
{
"last_affected": "3.1.5.1"
},
{
"last_affected": "3.1.6"
},
{
"last_affected": "3.1.7"
},
{
"last_affected": "3.1.8"
},
{
"last_affected": "3.1.9"
},
{
"last_affected": "3.1.10"
},
{
"last_affected": "3.1.11"
},
{
"last_affected": "3.1.12"
},
{
"last_affected": "3.1.12.1"
},
{
"last_affected": "3.1.12.2"
},
{
"last_affected": "3.1.12.3"
},
{
"last_affected": "3.1.13"
},
{
"last_affected": "3.1.14"
},
{
"last_affected": "3.1.15"
},
{
"last_affected": "3.1.16"
},
{
"last_affected": "3.1.17"
},
{
"last_affected": "3.1.18"
},
{
"last_affected": "3.1.19"
},
{
"last_affected": "3.1.20"
},
{
"last_affected": "3.1.21"
},
{
"last_affected": "3.1.22"
},
{
"last_affected": "3.2.0.1"
},
{
"last_affected": "3.2.0.2"
},
{
"last_affected": "3.2.0.3"
},
{
"last_affected": "3.2.0.4"
},
{
"last_affected": "3.2.0.5"
},
{
"last_affected": "3.2.0.6"
},
{
"last_affected": "3.2.0.7"
},
{
"last_affected": "3.2.0.8"
},
{
"last_affected": "3.2.0.9"
},
{
"last_affected": "3.2.0.10"
},
{
"last_affected": "3.2.0.11"
},
{
"last_affected": "3.2.0.12"
},
{
"last_affected": "3.2.0.13"
},
{
"last_affected": "3.2.0.14"
},
{
"last_affected": "3.2.0.15"
},
{
"last_affected": "3.2.0.16"
},
{
"last_affected": "3.2.0.17"
},
{
"last_affected": "3.2.0.18"
},
{
"last_affected": "3.2.0.19"
},
{
"last_affected": "3.2.1"
},
{
"last_affected": "3.2.2"
},
{
"last_affected": "3.2.3"
},
{
"last_affected": "3.2.4"
},
{
"last_affected": "3.2.5"
},
{
"last_affected": "3.2.6"
},
{
"last_affected": "3.2.7"
},
{
"last_affected": "3.2.8"
},
{
"last_affected": "3.2.9"
},
{
"last_affected": "3.2.10"
},
{
"last_affected": "3.2.11"
},
{
"last_affected": "3.2.12"
},
{
"last_affected": "3.2.13"
},
{
"last_affected": "3.3.0.1"
},
{
"last_affected": "3.3.0.2"
},
{
"last_affected": "3.3.0.3"
},
{
"last_affected": "3.3.1"
},
{
"last_affected": "3.3.2"
},
{
"last_affected": "3.3.3"
},
{
"last_affected": "3.3.4"
},
{
"last_affected": "3.3.5"
},
{
"last_affected": "3.3.6"
},
{
"last_affected": "3.3.7"
},
{
"last_affected": "3.3.8"
},
{
"last_affected": "3.3.9"
},
{
"last_affected": "3.3.10"
},
{
"last_affected": "3.3.11"
},
{
"last_affected": "3.3.12"
},
{
"last_affected": "3.3.13"
},
{
"last_affected": "3.3.14"
},
{
"last_affected": "3.4.0.1"
},
{
"last_affected": "3.4.0.2"
},
{
"last_affected": "3.4.0.3"
},
{
"last_affected": "3.4.1"
},
{
"last_affected": "3.4.2"
},
{
"last_affected": "3.4.3"
},
{
"last_affected": "3.4.4"
},
{
"last_affected": "3.4.4.1"
},
{
"last_affected": "3.4.4.2"
},
{
"last_affected": "3.4.8"
},
{
"last_affected": "3.4.9"
},
{
"last_affected": "3.4.10"
},
{
"last_affected": "3.4.11"
},
{
"last_affected": "3.4.12"
},
{
"last_affected": "3.4.13"
},
{
"last_affected": "3.4.14"
},
{
"last_affected": "3.5.0.1"
},
{
"last_affected": "3.5.0.2"
},
{
"last_affected": "3.5.0.3"
},
{
"last_affected": "3.5.0.4"
},
{
"last_affected": "3.5.1"
},
{
"last_affected": "3.5.2"
},
{
"last_affected": "3.5.3"
},
{
"last_affected": "3.5.4"
},
{
"last_affected": "3.5.5"
},
{
"last_affected": "3.5.6"
},
{
"last_affected": "3.5.7"
},
{
"last_affected": "3.5.8"
},
{
"last_affected": "3.5.9"
},
{
"last_affected": "3.5.10"
},
{
"last_affected": "3.5.11"
},
{
"last_affected": "3.5.12"
},
{
"last_affected": "3.5.13"
},
{
"last_affected": "3.5.14"
},
{
"last_affected": "3.5.15"
},
{
"last_affected": "3.5.16"
},
{
"last_affected": "4.0.1"
},
{
"last_affected": "4.0.2"
},
{
"last_affected": "4.0.3"
},
{
"last_affected": "4.0.4"
},
{
"last_affected": "4.0.5"
},
{
"last_affected": "4.0.6"
},
{
"last_affected": "4.0.7"
},
{
"last_affected": "4.0.8"
}
],
"cpe": [
"cpe:2.3:a:squid-cache:squid:3.1:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.0.1:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.0.2:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.0.3:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.0.4:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.0.5:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.0.6:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.0.7:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.0.8:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.0.9:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.0.10:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.0.11:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.0.12:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.0.13:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.0.14:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.0.15:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.0.16:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.0.17:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.0.18:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.1:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.2:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.3:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.4:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.5:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.5.1:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.6:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.7:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.8:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.9:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.10:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.11:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.12:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.12.1:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.12.2:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.12.3:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.13:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.14:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.15:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.16:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.17:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.18:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.19:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.20:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.21:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.22:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.0.1:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.0.2:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.0.3:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.0.4:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.0.5:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.0.6:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.0.7:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.0.8:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.0.9:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.0.10:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.0.11:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.0.12:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.0.13:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.0.14:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.0.15:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.0.16:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.0.17:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.0.18:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.0.19:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.1:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.2:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.3:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.4:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.5:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.6:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.7:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.8:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.9:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.10:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.11:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.12:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.13:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.3.0.1:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.3.0.2:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.3.0.3:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.3.1:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.3.2:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.3.3:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.3.4:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.3.5:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.3.6:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.3.7:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.3.8:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.3.9:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.3.10:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.3.11:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.3.12:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.3.13:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.3.14:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.4.0.1:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.4.0.2:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.4.0.3:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.4.1:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.4.2:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.4.3:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.4.4:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.4.4.1:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.4.4.2:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.4.8:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.4.9:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.4.10:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.4.11:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.4.12:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.4.13:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.4.14:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.5.0.1:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.5.0.2:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.5.0.3:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.5.0.4:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.5.1:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.5.2:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.5.3:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.5.4:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.5.5:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.5.6:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.5.7:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.5.8:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.5.9:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.5.10:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.5.11:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.5.12:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.5.13:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.5.14:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.5.15:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.5.16:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:4.0.1:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:4.0.2:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:4.0.3:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:4.0.4:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:4.0.5:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:4.0.6:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:4.0.7:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:4.0.8:*:*:*:*:*:*:*"
]
}