CVE-2016-4553

CVSS v3.0 8.6 (High)
86% Progress
CVSS v2.0 5 (Medium)
50% Progress
EPSS 56.32 % (98th)
56.32% Progress
Affected Products 3
Advisories 12

client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which allows remote attackers to conduct cache-poisoning attacks via an HTTP request.

Weaknesses
CWE-345
Insufficient Verification of Data Authenticity
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2016-05-10 19:59:00
(8 years ago)
Updated Date
2019-12-27 16:08:55
(4 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Canonical Ubuntu Linux 12.04 cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts
  Canonical Ubuntu Linux 14.04 cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts
  Canonical Ubuntu Linux 15.10 cpe:2.3:o:canonical:ubuntu_linux:15.10
  Canonical Ubuntu Linux 16.04 cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts

Configuration #2

    CPE23 From Up To
  Squid-cache Squid 3.5.17 and prior versions cpe:2.3:a:squid-cache:squid <= 3.5.17

Configuration #3

    CPE23 From Up To
  Squid-cache Squid 4.0.1 cpe:2.3:a:squid-cache:squid:4.0.1
  Squid-cache Squid 4.0.2 cpe:2.3:a:squid-cache:squid:4.0.2
  Squid-cache Squid 4.0.3 cpe:2.3:a:squid-cache:squid:4.0.3
  Squid-cache Squid 4.0.4 cpe:2.3:a:squid-cache:squid:4.0.4
  Squid-cache Squid 4.0.5 cpe:2.3:a:squid-cache:squid:4.0.5
  Squid-cache Squid 4.0.6 cpe:2.3:a:squid-cache:squid:4.0.6
  Squid-cache Squid 4.0.7 cpe:2.3:a:squid-cache:squid:4.0.7
  Squid-cache Squid 4.0.8 cpe:2.3:a:squid-cache:squid:4.0.8
  Squid-cache Squid 4.0.9 cpe:2.3:a:squid-cache:squid:4.0.9

Configuration #4

    CPE23 From Up To
  Oracle Linux 7 cpe:2.3:o:oracle:linux:7
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...