CVE-2016-5408: Oracle Linux

Critical severity, CVSS 9.8. EPSS: 4.4% chance of exploitation in the next 30 days.

Stack-based buffer overflow in the munge_other_line function in cachemgr.cgi in the squid package before 3.1.23-16.el6_8.6 in Red Hat Enterprise Linux 6 allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-4051.

Affected products

  • Oracle Linux: version 6 only
  • Red Hat Enterprise Linux Server: version 6.0 only
  • Red Hat Enterprise Linux Workstation: version 6.0 only

Published 2016-08-10. Last modified 2026-06-17.