Back
CVE-2016-5408
CRITICAL
Stack-based buffer overflow in the munge_other_line function in cachemgr.cgi in the squid package before 3.1.23-16.el6_8.6 in Red Hat Enterprise Linux 6 allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-4051.
Published: Aug 10, 2016
Modified: Jun 17, 2026
CWE-119
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (3)
| Vendor | Product | Version |
|---|---|---|
| oracle | linux | 6 |
| redhat | enterprise_linux_server | 6.0 |
| redhat | enterprise_linux_workstation | 6.0 |
GitHub Security Advisory GHSA-5f9j-8ghm-9gxx
Stack-based buffer overflow in the munge_other_line function in cachemgr.cgi in the squid package...
References (4)
- http://rhn.redhat.com/errata/RHSA-2016-1573.html Patch, Vendor Advisory
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-1573.html Patch, Vendor Advisory
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html Third Party Advisory
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
4.35%
Top 10% most likely to be exploited
Threat Score
40.5 / 100
Data Sources
NVD
EPSS
GitHub