Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-4554

Опубликовано: 10 мая 2016
Источник: debian
EPSS Средний

Описание

mime_header.cc in Squid before 3.5.18 allows remote attackers to bypass intended same-origin restrictions and possibly conduct cache-poisoning attacks via a crafted HTTP Host header, aka a "header smuggling" issue.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
squid3fixed3.5.19-1package
squidfixed4.1-1package

Примечания

  • http://www.squid-cache.org/Advisories/SQUID-2016_8.txt

  • http://www.squid-cache.org/Versions/v3/3.1/changesets/squid-3.1-10496.patch

  • http://www.squid-cache.org/Versions/v3/3.2/changesets/squid-3.2-11842.patch

  • http://www.squid-cache.org/Versions/v3/3.3/changesets/squid-3.3-12698.patch

  • http://www.squid-cache.org/Versions/v3/3.4/changesets/squid-3.4-13236.patch

  • http://www.squid-cache.org/Versions/v3/3.5/changesets/squid-3.5-14038.patch

  • Regression and fix: http://bugs.squid-cache.org/show_bug.cgi?id=4515

  • Complete patch for 3.4 branch: http://www.squid-cache.org/Versions/v3/3.4/changesets/SQUID-2016_8.patch

EPSS

Процентиль: 97%
0.40573
Средний

Связанные уязвимости

CVSS3: 8.6
ubuntu
больше 9 лет назад

mime_header.cc in Squid before 3.5.18 allows remote attackers to bypass intended same-origin restrictions and possibly conduct cache-poisoning attacks via a crafted HTTP Host header, aka a "header smuggling" issue.

redhat
больше 9 лет назад

mime_header.cc in Squid before 3.5.18 allows remote attackers to bypass intended same-origin restrictions and possibly conduct cache-poisoning attacks via a crafted HTTP Host header, aka a "header smuggling" issue.

CVSS3: 8.6
nvd
больше 9 лет назад

mime_header.cc in Squid before 3.5.18 allows remote attackers to bypass intended same-origin restrictions and possibly conduct cache-poisoning attacks via a crafted HTTP Host header, aka a "header smuggling" issue.

CVSS3: 8.6
github
больше 3 лет назад

mime_header.cc in Squid before 3.5.18 allows remote attackers to bypass intended same-origin restrictions and possibly conduct cache-poisoning attacks via a crafted HTTP Host header, aka a "header smuggling" issue.

suse-cvrf
около 9 лет назад

Security update for squid

EPSS

Процентиль: 97%
0.40573
Средний