CVE Vulnerabilities

CVE-2015-5400

Published: Sep 28, 2015 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
2.3 LOW
AV:A/AC:M/Au:S/C:P/I:N/A:N
RedHat/V3
Ubuntu
LOW

Squid before 3.5.6 does not properly handle CONNECT method peer responses when configured with cache_peer, which allows remote attackers to bypass intended restrictions and gain access to a backend proxy via a CONNECT request.

Affected Software

Name Vendor Start Version End Version
Fedora Fedoraproject 22 (including) 22 (including)
Squid3 Ubuntu devel *
Squid3 Ubuntu precise *
Squid3 Ubuntu trusty *
Squid3 Ubuntu upstream *
Squid3 Ubuntu utopic *
Squid3 Ubuntu vivid *
Squid3 Ubuntu wily *
Squid3 Ubuntu xenial *

References