CVE-2016-4553
Published: 10 May 2016
client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which allows remote attackers to conduct cache-poisoning attacks via an HTTP request.
Priority
CVSS 3 base score: 8.6
Notes
Author | Note |
---|---|
sbeattie | 3.2.0.11 and later versions up to and including 3.5.17 |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4553
- http://www.squid-cache.org/Advisories/SQUID-2016_7.txt
- https://ubuntu.com/security/notices/USN-2995-1
- NVD
- Launchpad
- Debian