Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-4553

Опубликовано: 10 мая 2016
Источник: debian

Описание

client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which allows remote attackers to conduct cache-poisoning attacks via an HTTP request.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
squid3fixed3.5.19-1package
squid3not-affectedwheezypackage
squidnot-affectedpackage

Примечания

  • http://www.squid-cache.org/Advisories/SQUID-2016_7.txt

  • Fix for 3.5.x: http://www.squid-cache.org/Versions/v3/3.5/changesets/squid-3.5-14039.patch

  • Fix for 3.5 relies on SBuf.

  • Fix for 3.4.x: http://www.squid-cache.org/Versions/v3/3.4/changesets/squid-3.4-13240.patch

Связанные уязвимости

CVSS3: 8.6
ubuntu
больше 9 лет назад

client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which allows remote attackers to conduct cache-poisoning attacks via an HTTP request.

redhat
больше 9 лет назад

client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which allows remote attackers to conduct cache-poisoning attacks via an HTTP request.

CVSS3: 8.6
nvd
больше 9 лет назад

client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which allows remote attackers to conduct cache-poisoning attacks via an HTTP request.

CVSS3: 8.6
github
больше 3 лет назад

client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which allows remote attackers to conduct cache-poisoning attacks via an HTTP request.

oracle-oval
больше 9 лет назад

ELSA-2016-1140: squid34 security update (MODERATE)