VYPR
Medium severity5.9NVD Advisory· Published Apr 19, 2016· Updated May 6, 2026

CVE-2016-2390

CVE-2016-2390

Description

The FwdState::connectedToPeer method in FwdState.cc in Squid before 3.5.14 and 4.0.x before 4.0.6 does not properly handle SSL handshake errors when built with the --with-openssl option, which allows remote attackers to cause a denial of service (application crash) via a plaintext HTTP message.

Affected products

3
  • Squid Cache/Squid3 versions
    cpe:2.3:a:squid-cache:squid:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:squid-cache:squid:*:*:*:*:*:*:*:*range: <=3.5.13
    • cpe:2.3:a:squid-cache:squid:4.0.4:*:*:*:*:*:*:*
    • cpe:2.3:a:squid-cache:squid:4.0.5:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

7

News mentions

0

No linked articles in our index yet.