CVE-2009-0801
published 2009-03-04CVE-2009-0801: Squid, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass…
PriorityP427medium5.4CVSS 2.0
AVNACHAuNCCINAN
EPSS
3.09%
86.3th percentile
Squid, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web page that causes a client to send HTTP requests with a modified Host header.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | squid | < squid 4.1-1 (bookworm) | squid 4.1-1 (bookworm) |
| squid | squid | >= 0 < 4.1-1 | 4.1-1 |
| squid | squid | >= 0 < 4.1-1 | 4.1-1 |
| squid | squid | >= 0 < 4.1-1 | 4.1-1 |
| squid | squid | >= 0 < 4.1-1 | 4.1-1 |
| squid | squid_web_proxy_cache | — | — |
| squid | squid_web_proxy_cache | — | — |
| squid | squid_web_proxy_cache | — | — |
| squid | squid_web_proxy_cache | — | — |
| squid | squid_web_proxy_cache | — | — |
| squid | squid_web_proxy_cache | — | — |
| squid | squid_web_proxy_cache | — | — |
| squid | squid_web_proxy_cache | — | — |
| squid | squid_web_proxy_cache | — | — |
| squid | squid_web_proxy_cache | — | — |
| squid | squid_web_proxy_cache | — | — |
| squid | squid_web_proxy_cache | — | — |
| squid | squid_web_proxy_cache | — | — |
| squid | squid_web_proxy_cache | — | — |
| squid | squid_web_proxy_cache | — | — |
| squid | squid_web_proxy_cache | — | — |
CVSS provenance
nvdv2.05.4MEDIUMAV:N/AC:H/Au:N/C:C/I:N/A:N
osv5.4MEDIUM
vendor_debian5.4LOW
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w87g-c2c7-4fx5: Squid, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to byp
ghsa_unreviewed·2022-05-02
CVE-2009-0801 [MEDIUM] GHSA-w87g-c2c7-4fx5: Squid, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to byp
Squid, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web page that causes a client to send HTTP requests with a modified Host header.
OSV
CVE-2009-0801: Squid, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to byp
osv·2009-03-04·CVSS 5.4
CVE-2009-0801 [MEDIUM] CVE-2009-0801: Squid, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to byp
Squid, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web page that causes a client to send HTTP requests with a modified Host header.
Red Hat
squid: Cache poisoning issue in HTTP Request handling
vendor_redhat·2016-05-06·CVSS 5.4
CVE-2016-4553 [MEDIUM] CWE-20 squid: Cache poisoning issue in HTTP Request handling
squid: Cache poisoning issue in HTTP Request handling
client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which allows remote attackers to conduct cache-poisoning attacks via an HTTP request.
An input validation flaw was found in the way Squid handled intercepted HTTP Request messages. An attacker could use this flaw to bypass the protection against issues related to CVE-2009-0801, and perform cache poisoning attacks on Squid.
Package: squid (Red Hat Enterprise Linux 5) - Not affected
Package: squid (Red Hat Enterprise Linux 6) - Not affected
Red Hat
squid: remote bypass of access controls
vendor_redhat·2009-02-23·CVSS 5.4
CVE-2009-0801 [MEDIUM] squid: remote bypass of access controls
squid: remote bypass of access controls
Squid, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web page that causes a client to send HTTP requests with a modified Host header.
It was found that when transparent interception mode was enabled in squid a remote attacker could bypass access controls implemented for certain web elements like Flash and Java and communicate with restricted intranet sites via crafted Host headers.
Package: squid (Red Hat Enterprise Linux 4) - Will not fix
Package: squid (Red Hat Enterprise Linux 5) - Will not fix
P
Debian
CVE-2009-0801: squid - Squid, when transparent interception mode is enabled, uses the HTTP Host header ...
vendor_debian·2009·CVSS 5.4
CVE-2009-0801 [MEDIUM] CVE-2009-0801: squid - Squid, when transparent interception mode is enabled, uses the HTTP Host header ...
Squid, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web page that causes a client to send HTTP requests with a modified Host header.
Scope: local
bookworm: resolved (fixed in 4.1-1)
bullseye: resolved (fixed in 4.1-1)
forky: resolved (fixed in 4.1-1)
sid: resolved (fixed in 4.1-1)
trixie: resolved (fixed in 4.1-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-4553 squid: Cache poisoning issue in HTTP Request handling
bugzilla·2016-05-09·CVSS 5.4
CVE-2016-4553 [MEDIUM] CVE-2016-4553 squid: Cache poisoning issue in HTTP Request handling
CVE-2016-4553 squid: Cache poisoning issue in HTTP Request handling
Due to incorrect data validation of intercepted HTTP Request messages Squid is vulnerable to clients bypassing the protection against CVE-2009-0801 related issues. This leads to cache poisoning.
External references:
http://www.squid-cache.org/Advisories/SQUID-2016_7.txt
Upstream fix:
http://www.squid-cache.org/Versions/v3/3.5/changesets/squid-3.5-14039.patch
Discussion:
Created squid tracking bugs for this issue:
Affects: fedora-all [bug 1334251]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2016:1139 https://access.redhat.com/errata/RHSA-2016:1139
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2016:1140 htt
Bugzilla
CVE-2009-0801 squid: remote bypass of access controls [Fedora]
bugzilla·2009-03-04·CVSS 5.4
CVE-2009-0801 [MEDIUM] CVE-2009-0801 squid: remote bypass of access controls [Fedora]
CVE-2009-0801 squid: remote bypass of access controls [Fedora]
F10 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
You can eventually use the following link to create the update request:
https://admin.fedoraproject.org/updates/new/?request=Stable&type_=security&release=Fedora%2010&bugs=488503,
---
This message is a reminder that Fedora 10 is nearing its end of life.
Approximately 30 (thirty) days from now Fedora will stop maintaining
and issuing updates for Fedora 10. It is Fedora's policy to close all
bug reports from releases that are no longer maintained. At that time
this bug will be closed as WONTFIX if it remains open with a Fedora
'version' of '10'.
Package Maintainer: If you wish for
Bugzilla
CVE-2009-0801 squid: remote bypass of access controls [F9]
bugzilla·2009-03-04·CVSS 5.4
CVE-2009-0801 [MEDIUM] CVE-2009-0801 squid: remote bypass of access controls [F9]
CVE-2009-0801 squid: remote bypass of access controls [F9]
F9 tracking bug: see blocks bug list for full details of the security issue(s).
[bug automatically created by: add-tracking-bugs]
Discussion:
You can eventually use the following link to create the update request:
https://admin.fedoraproject.org/updates/new/?request=Stable&type_=security&release=Fedora%209&bugs=488504,
---
This message is a reminder that Fedora 9 is nearing its end of life.
Approximately 30 (thirty) days from now Fedora will stop maintaining
and issuing updates for Fedora 9. It is Fedora's policy to close all
bug reports from releases that are no longer maintained. At that time
this bug will be closed as WONTFIX if it remains open with a Fedora
'version' of '9'.
Package Maintainer: If you wish for this bug
Bugzilla
CVE-2009-0801 squid: remote bypass of access controls
bugzilla·2009-03-04·CVSS 5.4
CVE-2009-0801 [MEDIUM] CVE-2009-0801 squid: remote bypass of access controls
CVE-2009-0801 squid: remote bypass of access controls
Common Vulnerabilities and Exposures assigned an identifier CVE-2009-0801 to
the following vulnerability:
Name: CVE-2009-0801
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0801
Assigned: 20090304
Reference: CERT-VN:VU#435052
Reference: URL: http://www.kb.cert.org/vuls/id/435052
Reference: BID:33858
Reference: URL: http://www.securityfocus.com/bid/33858
Squid, when transparent interception mode is enabled, uses the HTTP
Host header to determine the remote endpoint, which allows remote
attackers to bypass access controls for Flash, Java, Silverlight, and
probably other technologies, and possibly communicate with restricted
intranet sites, via a crafted web page that causes a client to send
HTTP requests with a modified Ho
2009-03-04
Published