Rechercher
Contactez-nous Suivez-nous sur Twitter En francais English Language
 

Freely subscribe to our NEWSLETTER

Newsletter FR

Newsletter EN

Vulnérabilités

Unsubscribe

Vigil@nce - Squid: HTTP header injection

March 2015 by Vigil@nce

This bulletin was written by Vigil@nce : http://vigilance.fr/offer

SYNTHESIS OF THE VULNERABILITY

An attacker can inject HTTP headers in Squid, in order to inject
or read data.

Impacted products: Squid

Severity: 2/4

Creation date: 23/02/2015

Revision date: 06/03/2015

DESCRIPTION OF THE VULNERABILITY

The Squid product implements a web proxy.

However, line feeds between HTTP headers are not correctly
processed. Technical details are unknown.

An attacker can therefore inject HTTP headers in Squid, in order
to inject or read data.

ACCESS TO THE COMPLETE VIGIL@NCE BULLETIN

http://vigilance.fr/vulnerability/Squid-HTTP-header-injection-16244


See previous articles

    

See next articles


Your podcast Here

New, you can have your Podcast here. Contact us for more information ask:
Marc Brami
Phone: +33 1 40 92 05 55
Mail: ipsimp@free.fr

All new podcasts