Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2015-3455

Опубликовано: 18 мая 2015
Источник: ubuntu
Приоритет: negligible
EPSS Низкий
CVSS2: 2.6

Описание

Squid 3.2.x before 3.2.14, 3.3.x before 3.3.14, 3.4.x before 3.4.13, and 3.5.x before 3.5.4, when configured with client-first SSL-bump, do not properly validate the domain or hostname fields of X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate.

РелизСтатусПримечание
devel

released

3.5.12-1ubuntu6
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [3.3.8-1ubuntu6.6]]
precise

not-affected

3.1.19-1ubuntu3.12.04.4
trusty

released

3.3.8-1ubuntu6.6
trusty/esm

DNE

trusty was released [3.3.8-1ubuntu6.6]
upstream

released

3.5.4,3.4.13,3.3.14,3.2.14
utopic

ignored

end of life
vivid

ignored

end of life
vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

Показывать по

EPSS

Процентиль: 83%
0.02109
Низкий

2.6 Low

CVSS2

Связанные уязвимости

redhat
больше 10 лет назад

Squid 3.2.x before 3.2.14, 3.3.x before 3.3.14, 3.4.x before 3.4.13, and 3.5.x before 3.5.4, when configured with client-first SSL-bump, do not properly validate the domain or hostname fields of X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate.

nvd
больше 10 лет назад

Squid 3.2.x before 3.2.14, 3.3.x before 3.3.14, 3.4.x before 3.4.13, and 3.5.x before 3.5.4, when configured with client-first SSL-bump, do not properly validate the domain or hostname fields of X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate.

debian
больше 10 лет назад

Squid 3.2.x before 3.2.14, 3.3.x before 3.3.14, 3.4.x before 3.4.13, a ...

github
больше 3 лет назад

Squid 3.2.x before 3.2.14, 3.3.x before 3.3.14, 3.4.x before 3.4.13, and 3.5.x before 3.5.4, when configured with client-first SSL-bump, do not properly validate the domain or hostname fields of X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate.

oracle-oval
почти 10 лет назад

ELSA-2015-2378: squid security and bug fix update (MODERATE)

EPSS

Процентиль: 83%
0.02109
Низкий

2.6 Low

CVSS2