CVE-2015-5400
Publication date 28 September 2015
Last updated 24 July 2024
Ubuntu priority
Squid before 3.5.6 does not properly handle CONNECT method peer responses when configured with cache_peer, which allows remote attackers to bypass intended restrictions and gain access to a backend proxy via a CONNECT request.
Status
Package | Ubuntu Release | Status |
---|---|---|
squid3 | 16.04 LTS xenial |
Fixed 3.5.12-1ubuntu6
|
14.04 LTS trusty | Not in release | |
Notes
mdeslaur
non-default configuration, and needs substantial backporting There are no current plans to fix this CVE in Ubuntu 12.04 LTS and Ubuntu 14.04 LTS.
Patch details
Package | Patch details |
---|---|
squid3 |