CVE-2016-4053 affects Squid 3.x before 3.5.17 and 4.x before 4.0.9, allowing remote attackers to obtain sensitive stack layout information via crafted Edge Side Includes (ESI) responses due to incorrect assert usage and compiler optimization. This vulnerability carries a CVSSv3 score of 3.7 (Low), indicating a network-based attack with high complexity, leading to a low impact on confidentiality. While it is on a "Hot List," there is no evidence of active exploitation in the wild (KEV: No), and no public exploit code is available on platforms like Metasploit or ExploitDB. Community discussion shows some awareness, with references to a NASL script and a markdown file on GitHub, but its EPSS score of 0.262030000 suggests a low probability of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0CPE matchmatch criteria | cpe:2.3:a:squid-cache:squid:3.0:*:*:*:*:*:*:* | ||
3.1CPE matchmatch criteria | cpe:2.3:a:squid-cache:squid:3.1:*:*:*:*:*:*:* | ||
3.1.0.1CPE matchmatch criteria | cpe:2.3:a:squid-cache:squid:3.1.0.1:*:*:*:*:*:*:* | ||
3.1.0.2CPE matchmatch criteria | cpe:2.3:a:squid-cache:squid:3.1.0.2:*:*:*:*:*:*:* | ||
3.1.0.3CPE matchmatch criteria | cpe:2.3:a:squid-cache:squid:3.1.0.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.