All errata/sisyphus/ALT-PU-2015-1900-1
ALT-PU-2015-1900-1

Package update squid in branch sisyphus

Version3.5.10-alt1
Published2015-10-21
Max severityMEDIUM
Severity:

Closed issues (2)

BDU:2015-11546
MEDIUM6.8

Уязвимость прокси-сервера Squid, позволяющая нарушителю обойти существующие ограничения и получить доступ к серверу

Published: 2015-10-13Modified: 2021-03-23
CVSS 2.0MEDIUM 6.8
CVSS:2.0/AV:N/AC:M/Au:N/C:P/I:P/A:P
CVE-2015-5400
MEDIUM6.8

Squid before 3.5.6 does not properly handle CONNECT method peer responses when configured with cache_peer, which allows remote attackers to bypass intended restrictions and gain access to a backend proxy via a CONNECT request.

Published: 2015-09-28Modified: 2025-04-12
CVSS 2.0MEDIUM 6.8
CVSS:2.0/AV:N/AC:M/Au:N/C:P/I:P/A:P
References