Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Edge Side Includes (ESI) parser in Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not check buffer limits during XML parsing, which allows remote HTTP servers to cause a denial of service (assertion failure and daemon exit) via a crafted XML document, related to esi/CustomParser.cc and esi/CustomParser.h.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Squid Edge Side Includes解析器拒绝服务漏洞
Vulnerability Description
Squid(全称Squid Cache)是一套代理服务器和Web缓存服务器软件。该软件提供缓存万维网、过滤流量、代理上网等功能。 Squid 3.5.15之前3.x版本和4.0.7之前4.x版本的Edge Side Includes(ESI)解析器中存在安全漏洞,该漏洞源于程序在解析XML期间没有检查缓冲区限制。远程攻击者可借助特制的XML文档利用该漏洞造成拒绝服务(断言失败和守护进程退出)。
CVSS Information
N/A
Vulnerability Type
N/A