CRLF injection vulnerability in Squid before 3.1.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted header in a response.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Squid | Squid-cache | * | 3.1.0.18 (including) |
| Squid | Ubuntu | lucid | * |
| Squid3 | Ubuntu | lucid | * |
| Squid3 | Ubuntu | upstream | * |