cbcvebase.
CVE-2016-4554
published 2016-05-10

CVE-2016-4554: mime_header.cc in Squid before 3.5.18 allows remote attackers to bypass intended same-origin restrictions and possibly conduct cache-poisoning attacks via a…

PriorityP259high8.6CVSS 3.0
AVNACLPRNUINSCCNIHAN
EPSS
38.89%
98.4th percentile
mime_header.cc in Squid before 3.5.18 allows remote attackers to bypass intended same-origin restrictions and possibly conduct cache-poisoning attacks via a crafted HTTP Host header, aka a "header smuggling" issue.

Affected

12 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiansquid< squid 4.1-1 (bookworm)squid 4.1-1 (bookworm)
oraclelinux
oraclelinux
squid-cachesquid<= 3.5.17
squidsquid>= 0 < 4.1-14.1-1
squidsquid>= 0 < 4.1-14.1-1
squidsquid>= 0 < 4.1-14.1-1
squidsquid>= 0 < 4.1-14.1-1

Detection & IOCsextracted from sources · hover to see the quote

  • Exploit vector is a crafted HTTP Host header used for header smuggling against Squid's mime_get_header_field() function; monitor for malformed or unexpected Host header values in HTTP requests processed by Squid acting as interception or reverse-proxy
  • The vulnerability resides in mime_header.cc (mime_get_header_field() function) in Squid before 3.5.18; target detection at Squid versions < 3.5.18
  • Attack can also be used for cache poisoning against clients not following RFC 7230; inspect Squid cache for unexpected or cross-origin content injected via manipulated Host headers
  • ·Squid must be operating in interception or reverse-proxy mode for the same-origin bypass impact to apply; standard forward-proxy deployments may have different exposure
  • ·Red Hat Enterprise Linux 5 will NOT receive a fix for this CVE; deployments on RHEL 5 remain permanently vulnerable
  • ·Vendor-supplied patches exist for multiple Squid branches (3.1, 3.3, 3.4, 3.5) at the squid-cache.org advisory page; apply the branch-appropriate patch if upgrading to 3.5.18+ is not immediately possible

CVSS provenance

nvdv3.08.6HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv8.6HIGH
vendor_debian8.6HIGH
vendor_redhat8.6HIGH
vendor_ubuntu8.2HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.