Oval Definition:oval:org.cisecurity:def:22
Revision Date:2016-02-08Version:2
Title:DSA-3327-1 -- squid3 -- security update
Description:Alex Rousskov of The Measurement Factory discovered that Squid3, a fully featured web proxy cache, does not correctly handle CONNECT method peer responses when configured with cache_peer and operating on explicit proxy traffic. This could allow remote clients to gain unrestricted access through a gateway proxy to its backend proxy.
Family:unixClass:patch
Status:ACCEPTEDReference(s):CVE-2015-5400
DSA-3327-1
Platform(s):Debian 8
Debian GNU/kFreeBSD 7.0
Debian GNU/Linux 7.0
Product(s):squid3
Definition Synopsis
  • Debian 7
  • Debian 7 is installed
  • AND GNU/Linux or GNU/kFreeBSD kernel
  • Debian GNU/Linux is installed
  • OR Debian GNU/kFreeBSD is installed
  • AND squid3 is earlier than 0:3.1.20-2.2+deb7u3
  • OR Debian 8
  • Debian 8 is installed
  • AND squid3 is earlier than 0:3.4.8-6+deb8u1
  • BACK