CVE-2015-5400
Publication date 28 September 2015
Last updated 24 July 2024
Ubuntu priority
Description
Squid before 3.5.6 does not properly handle CONNECT method peer responses when configured with cache_peer, which allows remote attackers to bypass intended restrictions and gain access to a backend proxy via a CONNECT request.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| squid3 | 16.04 LTS xenial |
Fixed 3.5.12-1ubuntu6
|
| 14.04 LTS trusty | Not in release | |
Notes
mdeslaur
non-default configuration, and needs substantial backporting There are no current plans to fix this CVE in Ubuntu 12.04 LTS and Ubuntu 14.04 LTS.
Patch details
| Package | Patch details |
|---|---|
| squid3 |