Incorrect HTTP Request header comparison in Squid HTTP Proxy 3.5.0.1 through 3.5.22, and 4.0.1 through 4.0.16 results in Collapsed Forwarding feature mistakenly identifying some private responses as being suitable for delivery to multiple clients.
References
Link | Resource |
---|---|
http://www.squid-cache.org/Advisories/SQUID-2016_10.txt | Mitigation Patch Vendor Advisory |
http://www.securitytracker.com/id/1037512 | Third Party Advisory VDB Entry |
http://www.securityfocus.com/bid/94953 | Third Party Advisory VDB Entry |
http://www.openwall.com/lists/oss-security/2016/12/18/1 | Mailing List Patch Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2017-01-27 09:59
Updated : 2017-02-27 18:37
NVD link : CVE-2016-10003
Mitre link : CVE-2016-10003
JSON object : View
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
Products Affected
squid-cache
- squid