CVE-2015-5400

Squid <3.5.6 - Auth Bypass

Title source: llm
STIX 2.1

Description

Squid before 3.5.6 does not properly handle CONNECT method peer responses when configured with cache_peer, which allows remote attackers to bypass intended restrictions and gain access to a backend proxy via a CONNECT request.

References (15)

Core 15
Core References
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/07/06/8
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1032873
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2016-May/183598.html
Exploit mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/07/17/14
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/07/09/12
Mailing List vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2016-08/msg00069.html
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2015/07/10/2
Vendor Advisory x_refsource_confirm
http://www.squid-cache.org/Advisories/SQUID-2015_2.txt
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2015/dsa-3327
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/75553

Scores

EPSS 0.1653
EPSS Percentile 96.7%

Details

CWE
CWE-264
Status published
Products (4)
debian/debian_linux 7.0
debian/debian_linux 8.0
fedoraproject/fedora 22
squid-cache/squid < 3.5.2
Published Sep 28, 2015
Tracked Since Feb 18, 2026