CVE-2016-4553
published 2016-05-10CVE-2016-4553: client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which allows remote…
PriorityP263high8.6CVSS 3.0
AVNACLPRNUINSCCNIHAN
EPSS
79.97%
99.6th percentile
client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which allows remote attackers to conduct cache-poisoning attacks via an HTTP request.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | squid | — | — |
| oracle | linux | — | — |
| squid-cache | squid | <= 3.5.17 | — |
| squid-cache | squid | — | — |
| squid-cache | squid | — | — |
| squid-cache | squid | — | — |
| squid-cache | squid | — | — |
| squid-cache | squid | — | — |
| squid-cache | squid | — | — |
| squid-cache | squid | — | — |
| squid-cache | squid | — | — |
| squid-cache | squid | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Squid cache poisoning via HTTP request with absolute-URI where Host header is not properly ignored — look for HTTP requests containing an absolute-URI (e.g., 'GET http://example.com/path HTTP/1.1') combined with a differing Host header value sent to a Squid proxy ↗
- →This vulnerability is a bypass of CVE-2009-0801 protections in Squid's intercepted HTTP request handling — detection should focus on intercepted (transparent proxy) HTTP traffic where absolute-URI and Host header disagree ↗
- →Upstream patch available for forensic diffing and rule development: http://www.squid-cache.org/Versions/v3/3.5/changesets/squid-3.5-14039.patch ↗
- →Refer to the official Squid advisory SQUID-2016_7 for detailed attack vector and affected configurations ↗
- ·Only Squid versions before 3.5.18 and 4.x before 4.0.10 are vulnerable; Red Hat Enterprise Linux 5 and 6 packages were assessed as not affected by the vendor ↗
- ·The vulnerability specifically affects intercepted (transparent proxy) HTTP request handling in Squid, not standard forward-proxy deployments ↗
CVSS provenance
nvdv3.08.6HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv8.6HIGH
vendor_debian8.6LOW
vendor_ubuntu8.2HIGH
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p6vj-j24g-56wp: client_side
ghsa_unreviewed·2022-05-13
CVE-2016-4553 [HIGH] CWE-345 GHSA-p6vj-j24g-56wp: client_side
client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which allows remote attackers to conduct cache-poisoning attacks via an HTTP request.
OSV
squid3 vulnerabilities
osv·2016-06-09·CVSS 8.2
CVE-2016-3947 [HIGH] squid3 vulnerabilities
squid3 vulnerabilities
Yuriy M. Kaminskiy discovered that the Squid pinger utility incorrectly
handled certain ICMPv6 packets. A remote attacker could use this issue to
cause Squid to crash, resulting in a denial of service, or possibly cause
Squid to leak information into log files. (CVE-2016-3947)
Yuriy M. Kaminskiy discovered that the Squid cachemgr.cgi tool incorrectly
handled certain crafted data. A remote attacker could use this issue to
cause Squid to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2016-4051)
It was discovered that Squid incorrectly handled certain Edge Side Includes
(ESI) responses. A remote attacker could possibly use this issue to cause
Squid to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-
OSV
CVE-2016-4553: client_side
osv·2016-05-10·CVSS 8.6
CVE-2016-4553 [HIGH] CVE-2016-4553: client_side
client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which allows remote attackers to conduct cache-poisoning attacks via an HTTP request.
Ubuntu
Squid vulnerabilities
vendor_ubuntu·2016-06-09·CVSS 8.2
CVE-2016-3947 [HIGH] Squid vulnerabilities
Title: Squid vulnerabilities
Summary: Several security issues were fixed in Squid.
Yuriy M. Kaminskiy discovered that the Squid pinger utility incorrectly
handled certain ICMPv6 packets. A remote attacker could use this issue to
cause Squid to crash, resulting in a denial of service, or possibly cause
Squid to leak information into log files. (CVE-2016-3947)
Yuriy M. Kaminskiy discovered that the Squid cachemgr.cgi tool incorrectly
handled certain crafted data. A remote attacker could use this issue to
cause Squid to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2016-4051)
It was discovered that Squid incorrectly handled certain Edge Side Includes
(ESI) responses. A remote attacker could possibly use this issue to cause
Squid to crash, resulting in a
Red Hat
squid: Cache poisoning issue in HTTP Request handling
vendor_redhat·2016-05-06·CVSS 5.4
CVE-2016-4553 [MEDIUM] CWE-20 squid: Cache poisoning issue in HTTP Request handling
squid: Cache poisoning issue in HTTP Request handling
client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which allows remote attackers to conduct cache-poisoning attacks via an HTTP request.
An input validation flaw was found in the way Squid handled intercepted HTTP Request messages. An attacker could use this flaw to bypass the protection against issues related to CVE-2009-0801, and perform cache poisoning attacks on Squid.
Package: squid (Red Hat Enterprise Linux 5) - Not affected
Package: squid (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2016-4553: squid - client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ig...
vendor_debian·2016·CVSS 8.6
CVE-2016-4553 [HIGH] CVE-2016-4553: squid - client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ig...
client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which allows remote attackers to conduct cache-poisoning attacks via an HTTP request.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-4553 CVE-2016-4554 CVE-2016-4555 CVE-2016-4556 squid: various flaws [fedora-all]
bugzilla·2016-05-09·CVSS 8.6
CVE-2016-4553 [HIGH] CVE-2016-4553 CVE-2016-4554 CVE-2016-4555 CVE-2016-4556 squid: various flaws [fedora-all]
CVE-2016-4553 CVE-2016-4554 CVE-2016-4555 CVE-2016-4556 squid: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
Bugzilla
CVE-2016-4553 squid: Cache poisoning issue in HTTP Request handling
bugzilla·2016-05-09·CVSS 5.4
CVE-2016-4553 [MEDIUM] CVE-2016-4553 squid: Cache poisoning issue in HTTP Request handling
CVE-2016-4553 squid: Cache poisoning issue in HTTP Request handling
Due to incorrect data validation of intercepted HTTP Request messages Squid is vulnerable to clients bypassing the protection against CVE-2009-0801 related issues. This leads to cache poisoning.
External references:
http://www.squid-cache.org/Advisories/SQUID-2016_7.txt
Upstream fix:
http://www.squid-cache.org/Versions/v3/3.5/changesets/squid-3.5-14039.patch
Discussion:
Created squid tracking bugs for this issue:
Affects: fedora-all [bug 1334251]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2016:1139 https://access.redhat.com/errata/RHSA-2016:1139
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6
Via RHSA-2016:1140 htt
http://bugs.squid-cache.org/show_bug.cgi?id=4501http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00040.htmlhttp://lists.opensuse.org/opensuse-updates/2016-08/msg00069.htmlhttp://www.debian.org/security/2016/dsa-3625http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.securitytracker.com/id/1035768http://www.squid-cache.org/Advisories/SQUID-2016_7.txthttp://www.squid-cache.org/Versions/v3/3.5/changesets/squid-3.5-14039.patchhttp://www.ubuntu.com/usn/USN-2995-1https://access.redhat.com/errata/RHSA-2016:1139https://access.redhat.com/errata/RHSA-2016:1140https://security.gentoo.org/glsa/201607-01http://bugs.squid-cache.org/show_bug.cgi?id=4501http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-08/msg00040.htmlhttp://lists.opensuse.org/opensuse-updates/2016-08/msg00069.htmlhttp://www.debian.org/security/2016/dsa-3625http://www.oracle.com/technetwork/topics/security/linuxbulletinapr2016-2952096.htmlhttp://www.securitytracker.com/id/1035768http://www.squid-cache.org/Advisories/SQUID-2016_7.txthttp://www.squid-cache.org/Versions/v3/3.5/changesets/squid-3.5-14039.patchhttp://www.ubuntu.com/usn/USN-2995-1https://access.redhat.com/errata/RHSA-2016:1139https://access.redhat.com/errata/RHSA-2016:1140https://security.gentoo.org/glsa/201607-01
2016-05-10
Published