← Back

CVE-2016-2390

nvd nist
Published: Apr 19, 2016Modified: May 6, 2026

JSON object

Loading...
5.9
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 2.2 / Impact: 3.6
Source: NVD

Description

The FwdState::connectedToPeer method in FwdState.cc in Squid before 3.5.14 and 4.0.x before 4.0.6 does not properly handle SSL handshake errors when built with the --with-openssl option, which allows remote attackers to cause a denial of service (application crash) via a plaintext HTTP message.

Affected (3)

Products: Squid Cache: Squid
1 product
Squid
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Squid Cache
Up to 3.5.13
Version 4.0.4
Version 4.0.5

Timeline

No history available yet.