Vulnerability CVE-2016-4553


Published: 2016-05-10

Description:
client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which allows remote attackers to conduct cache-poisoning attacks via an HTTP request.

CVSS2 => (AV:N/AC:L/Au:N/C:N/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
Partial
None
Affected software
Squid-cache -> Squid 
Oracle -> Linux 
Canonical -> Ubuntu linux 

 References:
http://bugs.squid-cache.org/show_bug.cgi?id=4501
http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.html
http://www.securitytracker.com/id/1035768
http://www.squid-cache.org/Advisories/SQUID-2016_7.txt
http://www.squid-cache.org/Versions/v3/3.5/changesets/squid-3.5-14039.patch
http://www.ubuntu.com/usn/USN-2995-1

Copyright 2024, cxsecurity.com

 

Back to Top