Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-10003

Опубликовано: 27 янв. 2017
Источник: debian
EPSS Низкий

Описание

Incorrect HTTP Request header comparison in Squid HTTP Proxy 3.5.0.1 through 3.5.22, and 4.0.1 through 4.0.16 results in Collapsed Forwarding feature mistakenly identifying some private responses as being suitable for delivery to multiple clients.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
squid3fixed3.5.23-1package
squid3not-affectedjessiepackage
squid3not-affectedwheezypackage

Примечания

  • Marked as not-affected, vulnerable vulnerability not present due to

  • the collapsed_forwarding directive beeing added in 3.5.0.1 only

  • http://www.squid-cache.org/Advisories/SQUID-2016_10.txt

  • http://www.squid-cache.org/Versions/v4/changesets/squid-4-14956.patch

  • http://www.squid-cache.org/Versions/v3/3.5/changesets/SQUID-2016_10_a.patch (for squid-3.5 excluding 3.5.22)

  • http://www.squid-cache.org/Versions/v3/3.5/changesets/squid-3.5-14127.patch (for squid 3.5.22 only)

  • Vulnerable Squid Versions:

  • 3.5.0.1 up to and including 3.5.22

  • 4.0.1 up to and including 4.0.16

  • https://www.openwall.com/lists/oss-security/2016/12/17/1

EPSS

Процентиль: 91%
0.04772
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 9 лет назад

Incorrect HTTP Request header comparison in Squid HTTP Proxy 3.5.0.1 through 3.5.22, and 4.0.1 through 4.0.16 results in Collapsed Forwarding feature mistakenly identifying some private responses as being suitable for delivery to multiple clients.

CVSS3: 3.7
redhat
больше 9 лет назад

Incorrect HTTP Request header comparison in Squid HTTP Proxy 3.5.0.1 through 3.5.22, and 4.0.1 through 4.0.16 results in Collapsed Forwarding feature mistakenly identifying some private responses as being suitable for delivery to multiple clients.

CVSS3: 7.5
nvd
больше 9 лет назад

Incorrect HTTP Request header comparison in Squid HTTP Proxy 3.5.0.1 through 3.5.22, and 4.0.1 through 4.0.16 results in Collapsed Forwarding feature mistakenly identifying some private responses as being suitable for delivery to multiple clients.

CVSS3: 7.5
github
больше 4 лет назад

Incorrect HTTP Request header comparison in Squid HTTP Proxy 3.5.0.1 through 3.5.22, and 4.0.1 through 4.0.16 results in Collapsed Forwarding feature mistakenly identifying some private responses as being suitable for delivery to multiple clients.

suse-cvrf
больше 9 лет назад

Security update for squid

EPSS

Процентиль: 91%
0.04772
Низкий