Логотип exploitDog
bind:"BDU:2021-01748" OR bind:"CVE-2019-18678"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2021-01748" OR bind:"CVE-2019-18678"

Количество 14

Количество 14

fstec логотип

BDU:2021-01748

больше 5 лет назад

Уязвимость заголовка запросов прокси-сервера Squid, связанная с недостатками обработки HTTP-запросов, позволяющая нарушителю оказать воздействие на целостность данных

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2019-18678

больше 5 лет назад

An issue was discovered in Squid 3.x and 4.x through 4.8. It allows attackers to smuggle HTTP requests through frontend software to a Squid instance that splits the HTTP Request pipeline differently. The resulting Response messages corrupt caches (between a client and Squid) with attacker-controlled content at arbitrary URLs. Effects are isolated to software between the attacker client and Squid. There are no effects on Squid itself, nor on any upstream servers. The issue is related to a request header containing whitespace between a header name and a colon.

CVSS3: 5.3
EPSS: Средний
redhat логотип

CVE-2019-18678

больше 5 лет назад

An issue was discovered in Squid 3.x and 4.x through 4.8. It allows attackers to smuggle HTTP requests through frontend software to a Squid instance that splits the HTTP Request pipeline differently. The resulting Response messages corrupt caches (between a client and Squid) with attacker-controlled content at arbitrary URLs. Effects are isolated to software between the attacker client and Squid. There are no effects on Squid itself, nor on any upstream servers. The issue is related to a request header containing whitespace between a header name and a colon.

CVSS3: 6.8
EPSS: Средний
nvd логотип

CVE-2019-18678

больше 5 лет назад

An issue was discovered in Squid 3.x and 4.x through 4.8. It allows attackers to smuggle HTTP requests through frontend software to a Squid instance that splits the HTTP Request pipeline differently. The resulting Response messages corrupt caches (between a client and Squid) with attacker-controlled content at arbitrary URLs. Effects are isolated to software between the attacker client and Squid. There are no effects on Squid itself, nor on any upstream servers. The issue is related to a request header containing whitespace between a header name and a colon.

CVSS3: 5.3
EPSS: Средний
debian логотип

CVE-2019-18678

больше 5 лет назад

An issue was discovered in Squid 3.x and 4.x through 4.8. It allows at ...

CVSS3: 5.3
EPSS: Средний
github логотип

GHSA-jvgf-c7c2-w98p

около 3 лет назад

An issue was discovered in Squid 3.x and 4.x through 4.8. It allows attackers to smuggle HTTP requests through frontend software to a Squid instance that splits the HTTP Request pipeline differently. The resulting Response messages corrupt caches (between a client and Squid) with attacker-controlled content at arbitrary URLs. Effects are isolated to software between the attacker client and Squid. There are no effects on Squid itself, nor on any upstream servers. The issue is related to a request header containing whitespace between a header name and a colon.

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2019:3067-1

больше 5 лет назад

Security update for squid

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:0661-1

больше 5 лет назад

Security update for squid

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:2541-1

больше 5 лет назад

Security update for squid

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:2540-1

больше 5 лет назад

Security update for squid

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:2975-1

больше 5 лет назад

Security update for squid

EPSS: Низкий
rocky логотип

RLSA-2020:4743

больше 4 лет назад

Moderate: squid:4 security, bug fix, and enhancement update

EPSS: Низкий
oracle-oval логотип

ELSA-2020-4743

больше 4 лет назад

ELSA-2020-4743: squid:4 security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:14460-1

почти 5 лет назад

Security update for squid3

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2021-01748

Уязвимость заголовка запросов прокси-сервера Squid, связанная с недостатками обработки HTTP-запросов, позволяющая нарушителю оказать воздействие на целостность данных

CVSS2: 5
13%
Средний
больше 5 лет назад
ubuntu логотип
CVE-2019-18678

An issue was discovered in Squid 3.x and 4.x through 4.8. It allows attackers to smuggle HTTP requests through frontend software to a Squid instance that splits the HTTP Request pipeline differently. The resulting Response messages corrupt caches (between a client and Squid) with attacker-controlled content at arbitrary URLs. Effects are isolated to software between the attacker client and Squid. There are no effects on Squid itself, nor on any upstream servers. The issue is related to a request header containing whitespace between a header name and a colon.

CVSS3: 5.3
13%
Средний
больше 5 лет назад
redhat логотип
CVE-2019-18678

An issue was discovered in Squid 3.x and 4.x through 4.8. It allows attackers to smuggle HTTP requests through frontend software to a Squid instance that splits the HTTP Request pipeline differently. The resulting Response messages corrupt caches (between a client and Squid) with attacker-controlled content at arbitrary URLs. Effects are isolated to software between the attacker client and Squid. There are no effects on Squid itself, nor on any upstream servers. The issue is related to a request header containing whitespace between a header name and a colon.

CVSS3: 6.8
13%
Средний
больше 5 лет назад
nvd логотип
CVE-2019-18678

An issue was discovered in Squid 3.x and 4.x through 4.8. It allows attackers to smuggle HTTP requests through frontend software to a Squid instance that splits the HTTP Request pipeline differently. The resulting Response messages corrupt caches (between a client and Squid) with attacker-controlled content at arbitrary URLs. Effects are isolated to software between the attacker client and Squid. There are no effects on Squid itself, nor on any upstream servers. The issue is related to a request header containing whitespace between a header name and a colon.

CVSS3: 5.3
13%
Средний
больше 5 лет назад
debian логотип
CVE-2019-18678

An issue was discovered in Squid 3.x and 4.x through 4.8. It allows at ...

CVSS3: 5.3
13%
Средний
больше 5 лет назад
github логотип
GHSA-jvgf-c7c2-w98p

An issue was discovered in Squid 3.x and 4.x through 4.8. It allows attackers to smuggle HTTP requests through frontend software to a Squid instance that splits the HTTP Request pipeline differently. The resulting Response messages corrupt caches (between a client and Squid) with attacker-controlled content at arbitrary URLs. Effects are isolated to software between the attacker client and Squid. There are no effects on Squid itself, nor on any upstream servers. The issue is related to a request header containing whitespace between a header name and a colon.

13%
Средний
около 3 лет назад
suse-cvrf логотип
SUSE-SU-2019:3067-1

Security update for squid

больше 5 лет назад
suse-cvrf логотип
SUSE-SU-2020:0661-1

Security update for squid

больше 5 лет назад
suse-cvrf логотип
openSUSE-SU-2019:2541-1

Security update for squid

больше 5 лет назад
suse-cvrf логотип
openSUSE-SU-2019:2540-1

Security update for squid

больше 5 лет назад
suse-cvrf логотип
SUSE-SU-2019:2975-1

Security update for squid

больше 5 лет назад
rocky логотип
RLSA-2020:4743

Moderate: squid:4 security, bug fix, and enhancement update

больше 4 лет назад
oracle-oval логотип
ELSA-2020-4743

ELSA-2020-4743: squid:4 security, bug fix, and enhancement update (MODERATE)

больше 4 лет назад
suse-cvrf логотип
SUSE-SU-2020:14460-1

Security update for squid3

почти 5 лет назад

Уязвимостей на страницу