Описание
Squid before 4.4 has XSS via a crafted X.509 certificate during HTTP(S) error page generation for certificate errors.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| squid | fixed | 4.4-1 | package | |
| squid3 | removed | package |
Примечания
http://www.squid-cache.org/Advisories/SQUID-2018_4.txt
Squid in Debian builds without TLS support
EPSS
Процентиль: 93%
0.10782
Средний
Связанные уязвимости
CVSS3: 6.1
ubuntu
около 7 лет назад
Squid before 4.4 has XSS via a crafted X.509 certificate during HTTP(S) error page generation for certificate errors.
CVSS3: 5.6
redhat
больше 7 лет назад
Squid before 4.4 has XSS via a crafted X.509 certificate during HTTP(S) error page generation for certificate errors.
CVSS3: 6.1
nvd
около 7 лет назад
Squid before 4.4 has XSS via a crafted X.509 certificate during HTTP(S) error page generation for certificate errors.
CVSS3: 6.1
github
больше 3 лет назад
Squid before 4.4 has XSS via a crafted X.509 certificate during HTTP(S) error page generation for certificate errors.
EPSS
Процентиль: 93%
0.10782
Средний