PT-2016-6015 · Squid+5 · Squid+6
Jianjun Chen
·
Published
2016-05-10
·
Updated
2019-12-27
·
CVE-2016-4554
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Squid versions prior to 3.5.18
Description
The issue allows remote attackers to bypass intended same-origin restrictions and possibly conduct cache-poisoning attacks via a crafted HTTP Host header, also known as a "header smuggling" issue. This is related to the
mime header.cc file in Squid.Recommendations
For versions prior to 3.5.18, update to version 3.5.18 or later to resolve the issue. As a temporary workaround, consider restricting access to the
mime header.cc functionality until a patch is available. Avoid using manipulated HTTP Host headers in the affected Squid versions until the issue is resolved.Fix
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Centos
Red Hat
Squid
Squid Cache
Suse
Ubuntu