mime_header.cc in Squid before 3.5.18 allows remote attackers to bypass intended same-origin restrictions and possibly conduct cache-poisoning attacks via a crafted HTTP Host header, aka a "header smuggling" issue.
CVSS Details
- CVSS 3.1 Base Score: 8.6
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade squid | Sep 20, 2017 | May 10, 2016 |
| Amazon_linux | — | Upgrade squid | Jun 15, 2016 | May 10, 2016 |
| Centos_linux | — | Upgrade squidUpgrade squid34Upgrade squid-sysvinit | May 31, 2016 | May 10, 2016 |
| Debian | — | Upgrade squidUpgrade squid3 | Jul 22, 2016 | May 10, 2016 |
| Freebsd | — | Upgrade squidUpgrade squid-devel | Dec 10, 2025 | May 7, 2016 |
| Gentoo Linux | — | Upgrade net-proxy/squid. | Oct 30, 2017 | May 10, 2016 |
| Huawei Euleros 2_0_sp1 | — | Upgrade squid | Nov 30, 2017 | May 10, 2016 |
| Oracle Solaris | — | Upgrade entire/ to version 11.4-11.4.0.0.1.15.0 on Solaris 11.4 | Oct 19, 2018 | May 10, 2016 |
| Oracle_linux | — | Upgrade squidUpgrade squid-sysvinitUpgrade squid34 | May 31, 2016 | May 10, 2016 |
| Redhat_linux | — | Upgrade squidUpgrade squid-debuginfoNo solution existsUpgrade squid34Upgrade squid-sysvinitUpgrade squid34-debuginfo | Jun 1, 2016 | May 10, 2016 |
| Suse | — | Upgrade squid3Upgrade squid | Aug 26, 2016 | May 10, 2016 |
| Ubuntu | — | Upgrade squid-cgiUpgrade squid3 | Jun 9, 2016 | May 10, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub