CVE-2016-10003
Summary
| CVE | CVE-2016-10003 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-01-27 17:59:00 UTC |
| Updated | 2024-02-02 03:03:00 UTC |
| Description | Incorrect HTTP Request header comparison in Squid HTTP Proxy 3.5.0.1 through 3.5.22, and 4.0.1 through 4.0.16 results in Collapsed Forwarding feature mistakenly identifying some private responses as being suitable for delivery to multiple clients. |
Risk And Classification
Problem Types: CWE-697
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Squid-cache | Squid | All | All | All | All |
| Application | Squid-cache | Squid | 3.5.0.1 | All | All | All |
| Application | Squid-cache | Squid | 3.5.0.2 | All | All | All |
| Application | Squid-cache | Squid | 3.5.0.3 | All | All | All |
| Application | Squid-cache | Squid | 3.5.0.4 | All | All | All |
| Application | Squid-cache | Squid | 3.5.1 | All | All | All |
| Application | Squid-cache | Squid | 3.5.10 | All | All | All |
| Application | Squid-cache | Squid | 3.5.11 | All | All | All |
| Application | Squid-cache | Squid | 3.5.12 | All | All | All |
| Application | Squid-cache | Squid | 3.5.13 | All | All | All |
| Application | Squid-cache | Squid | 3.5.14 | All | All | All |
| Application | Squid-cache | Squid | 3.5.15 | All | All | All |
| Application | Squid-cache | Squid | 3.5.16 | All | All | All |
| Application | Squid-cache | Squid | 3.5.17 | All | All | All |
| Application | Squid-cache | Squid | 3.5.18 | All | All | All |
| Application | Squid-cache | Squid | 3.5.19 | All | All | All |
| Application | Squid-cache | Squid | 3.5.2 | All | All | All |
| Application | Squid-cache | Squid | 3.5.20 | All | All | All |
| Application | Squid-cache | Squid | 3.5.21 | All | All | All |
| Application | Squid-cache | Squid | 3.5.22 | All | All | All |
| Application | Squid-cache | Squid | 3.5.3 | All | All | All |
| Application | Squid-cache | Squid | 3.5.4 | All | All | All |
| Application | Squid-cache | Squid | 3.5.5 | All | All | All |
| Application | Squid-cache | Squid | 3.5.6 | All | All | All |
| Application | Squid-cache | Squid | 3.5.7 | All | All | All |
| Application | Squid-cache | Squid | 3.5.8 | All | All | All |
| Application | Squid-cache | Squid | 3.5.9 | All | All | All |
| Application | Squid-cache | Squid | 4.0.1 | All | All | All |
| Application | Squid-cache | Squid | 4.0.10 | All | All | All |
| Application | Squid-cache | Squid | 4.0.11 | All | All | All |
| Application | Squid-cache | Squid | 4.0.12 | All | All | All |
| Application | Squid-cache | Squid | 4.0.13 | All | All | All |
| Application | Squid-cache | Squid | 4.0.14 | All | All | All |
| Application | Squid-cache | Squid | 4.0.15 | All | All | All |
| Application | Squid-cache | Squid | 4.0.16 | All | All | All |
| Application | Squid-cache | Squid | 4.0.2 | All | All | All |
| Application | Squid-cache | Squid | 4.0.3 | All | All | All |
| Application | Squid-cache | Squid | 4.0.4 | All | All | All |
| Application | Squid-cache | Squid | 4.0.5 | All | All | All |
| Application | Squid-cache | Squid | 4.0.6 | All | All | All |
| Application | Squid-cache | Squid | 4.0.7 | All | All | All |
| Application | Squid-cache | Squid | 4.0.8 | All | All | All |
| Application | Squid-cache | Squid | 4.0.9 | All | All | All |
| Application | Squid-cache | Squid | 3.5.0.1 | All | All | All |
| Application | Squid-cache | Squid | 3.5.0.2 | All | All | All |
| Application | Squid-cache | Squid | 3.5.0.3 | All | All | All |
| Application | Squid-cache | Squid | 3.5.0.4 | All | All | All |
| Application | Squid-cache | Squid | 3.5.1 | All | All | All |
| Application | Squid-cache | Squid | 3.5.10 | All | All | All |
| Application | Squid-cache | Squid | 3.5.11 | All | All | All |
| Application | Squid-cache | Squid | 3.5.12 | All | All | All |
| Application | Squid-cache | Squid | 3.5.13 | All | All | All |
| Application | Squid-cache | Squid | 3.5.14 | All | All | All |
| Application | Squid-cache | Squid | 3.5.15 | All | All | All |
| Application | Squid-cache | Squid | 3.5.16 | All | All | All |
| Application | Squid-cache | Squid | 3.5.17 | All | All | All |
| Application | Squid-cache | Squid | 3.5.18 | All | All | All |
| Application | Squid-cache | Squid | 3.5.19 | All | All | All |
| Application | Squid-cache | Squid | 3.5.2 | All | All | All |
| Application | Squid-cache | Squid | 3.5.20 | All | All | All |
| Application | Squid-cache | Squid | 3.5.21 | All | All | All |
| Application | Squid-cache | Squid | 3.5.22 | All | All | All |
| Application | Squid-cache | Squid | 3.5.3 | All | All | All |
| Application | Squid-cache | Squid | 3.5.4 | All | All | All |
| Application | Squid-cache | Squid | 3.5.5 | All | All | All |
| Application | Squid-cache | Squid | 3.5.6 | All | All | All |
| Application | Squid-cache | Squid | 3.5.7 | All | All | All |
| Application | Squid-cache | Squid | 3.5.8 | All | All | All |
| Application | Squid-cache | Squid | 3.5.9 | All | All | All |
| Application | Squid-cache | Squid | 4.0.1 | All | All | All |
| Application | Squid-cache | Squid | 4.0.10 | All | All | All |
| Application | Squid-cache | Squid | 4.0.11 | All | All | All |
| Application | Squid-cache | Squid | 4.0.12 | All | All | All |
| Application | Squid-cache | Squid | 4.0.13 | All | All | All |
| Application | Squid-cache | Squid | 4.0.14 | All | All | All |
| Application | Squid-cache | Squid | 4.0.15 | All | All | All |
| Application | Squid-cache | Squid | 4.0.16 | All | All | All |
| Application | Squid-cache | Squid | 4.0.2 | All | All | All |
| Application | Squid-cache | Squid | 4.0.3 | All | All | All |
| Application | Squid-cache | Squid | 4.0.4 | All | All | All |
| Application | Squid-cache | Squid | 4.0.5 | All | All | All |
| Application | Squid-cache | Squid | 4.0.6 | All | All | All |
| Application | Squid-cache | Squid | 4.0.7 | All | All | All |
| Application | Squid-cache | Squid | 4.0.8 | All | All | All |
| Application | Squid-cache | Squid | 4.0.9 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.squid-cache.org/Advisories/SQUID-2016_10.txt | CONFIRM | www.squid-cache.org | Mitigation, Patch, Vendor Advisory |
| oss-security - Re: CVE Request - squid HTTP proxy multiple Information Disclosure issues | MLIST | www.openwall.com | Mailing List, Patch, Third Party Advisory |
| Squid Header Comparison Bug Lets Remote Users Obtain Potentially Sensitive Information on the Target System - SecurityTracker | SECTRACK | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Squid HTTP proxy Multiple Information Disclosure Vulnerabilities | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.