CVE Vulnerabilities

CVE-2012-2213

Published: Apr 28, 2012 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
6.4 LOW
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

Squid 3.1.9 allows remote attackers to bypass the access configuration for the CONNECT method by providing an arbitrary allowed hostname in the Host HTTP header. NOTE: this issue might not be reproducible, because the researcher is unable to provide a squid.conf file for a vulnerable system, and the observed behavior is consistent with a squid.conf file that was (perhaps inadvertently) designed to allow access based on a req_header Host acl regex that matches www.uol.com.br

Affected Software

NameVendorStart VersionEnd Version
SquidSquid-cache3.1.9 (including)3.1.9 (including)
SquidUbuntuhardy*
SquidUbuntulucid*
SquidUbuntunatty*
SquidUbuntuoneiric*
Squid3Ubuntudevel*
Squid3Ubuntuhardy*
Squid3Ubuntulucid*
Squid3Ubuntunatty*
Squid3Ubuntuoneiric*
Squid3Ubuntuprecise*
Squid3Ubuntuquantal*
Squid3Ubunturaring*

References