Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-4553

Опубликовано: 10 мая 2016
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS2: 5
CVSS3: 8.6

Описание

client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which allows remote attackers to conduct cache-poisoning attacks via an HTTP request.

РелизСтатусПримечание
devel

released

3.5.12-1ubuntu8
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was released [3.3.8-1ubuntu6.8]]
esm-infra/xenial

released

3.5.12-1ubuntu7.2
precise

not-affected

3.2.x and newer only
trusty

released

3.3.8-1ubuntu6.8
trusty/esm

DNE

trusty was released [3.3.8-1ubuntu6.8]
upstream

released

3.5.18,4.0.10
vivid/stable-phone-overlay

DNE

vivid/ubuntu-core

DNE

wily

released

3.3.8-1ubuntu16.3

Показывать по

EPSS

Процентиль: 97%
0.39528
Средний

5 Medium

CVSS2

8.6 High

CVSS3

Связанные уязвимости

redhat
больше 9 лет назад

client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which allows remote attackers to conduct cache-poisoning attacks via an HTTP request.

CVSS3: 8.6
nvd
больше 9 лет назад

client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which allows remote attackers to conduct cache-poisoning attacks via an HTTP request.

CVSS3: 8.6
debian
больше 9 лет назад

client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not p ...

CVSS3: 8.6
github
больше 3 лет назад

client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which allows remote attackers to conduct cache-poisoning attacks via an HTTP request.

oracle-oval
больше 9 лет назад

ELSA-2016-1140: squid34 security update (MODERATE)

EPSS

Процентиль: 97%
0.39528
Средний

5 Medium

CVSS2

8.6 High

CVSS3