CVE-2016-4553
10.05.2016, 19:59
client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which allows remote attackers to conduct cache-poisoning attacks via an HTTP request.Enginsight
Vendor | Product | Version |
---|---|---|
canonical | ubuntu_linux | 12.04 |
canonical | ubuntu_linux | 14.04 |
canonical | ubuntu_linux | 15.10 |
canonical | ubuntu_linux | 16.04 |
squid-cache | squid | 𝑥 ≤ 3.5.17 |
squid-cache | squid | 4.0.1 |
squid-cache | squid | 4.0.2 |
squid-cache | squid | 4.0.3 |
squid-cache | squid | 4.0.4 |
squid-cache | squid | 4.0.5 |
squid-cache | squid | 4.0.6 |
squid-cache | squid | 4.0.7 |
squid-cache | squid | 4.0.8 |
squid-cache | squid | 4.0.9 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References