Back

MEDIUM

squid: remote bypass of access controls

Published Mar 4, 2009

Description

Squid, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web page that causes a client to send HTTP requests with a modified Host header.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 4, 2009
Updated Sep 17, 2024
Reserved Mar 4, 2009
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Low
Public date Feb 23, 2009