Debian Security Advisory

DLA-286-1 squid3 -- LTS security update

Date Reported:
30 Jul 2015
Affected Packages:
squid3
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 793128.
In Mitre's CVE dictionary: CVE-2015-5400.
More information:

Alex Rousskov discovered that Squid configured with cache_peer and operating on explicit proxy traffic does not correctly handle CONNECT method peer responses. In some configurations, it allows remote clients to bypass security in an explicit gateway proxy.

For Debian 6 Squeeze, this problem has been fixed in squid3 version 3.1.6-1.2+squeeze5. We recommend that you upgrade your squid3 packages.