Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-0881

Опубликовано: 20 фев. 2015
Источник: debian
EPSS Низкий

Описание

CRLF injection vulnerability in Squid before 3.1.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted header in a response.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
squidfixed4.1-1package
squidno-dsasqueezepackage
squidno-dsawheezypackage
squid3fixed3.1.1-1package

Примечания

  • https://www.openwall.com/lists/oss-security/2015/03/01/2

  • Patch: http://www.squid-cache.org/Versions/v3/3.1/changesets/b9619.patch

  • https://jvn.jp/en/jp/JVN64455813/index.html

EPSS

Процентиль: 89%
0.04383
Низкий

Связанные уязвимости

ubuntu
почти 11 лет назад

CRLF injection vulnerability in Squid before 3.1.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted header in a response.

redhat
почти 11 лет назад

CRLF injection vulnerability in Squid before 3.1.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted header in a response.

nvd
почти 11 лет назад

CRLF injection vulnerability in Squid before 3.1.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted header in a response.

github
больше 3 лет назад

CRLF injection vulnerability in Squid before 3.1.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted header in a response.

EPSS

Процентиль: 89%
0.04383
Низкий