CRLF injection vulnerability in Squid before 3.1.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted header in a response.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Squid | Squid-cache | * | 3.1.0.18 (including) |
Squid | Ubuntu | lucid | * |
Squid3 | Ubuntu | lucid | * |
Squid3 | Ubuntu | upstream | * |