Debian Security Advisory
DLA-286-1 squid3 -- LTS security update
- Date Reported:
- 30 Jul 2015
- Affected Packages:
- squid3
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 793128.
In Mitre's CVE dictionary: CVE-2015-5400. - More information:
-
Alex Rousskov discovered that Squid configured with cache_peer and operating on explicit proxy traffic does not correctly handle CONNECT method peer responses. In some configurations, it allows remote clients to bypass security in an explicit gateway proxy.
For Debian 6 Squeeze, this problem has been fixed in squid3 version 3.1.6-1.2+squeeze5. We recommend that you upgrade your squid3 packages.