Incorrect processing of responses to If-None-Modified HTTP conditional requests in Squid HTTP Proxy 3.1.10 through 3.1.23, 3.2.0.3 through 3.5.22, and 4.0.1 through 4.0.16 leads to client-specific Cookie data being leaked to other clients. Attack requests can easily be crafted by a client to probe a cache for this information.
{
"unresolved_ranges": [
{
"extracted_events": [
{
"last_affected": "3.4.0.4"
}
],
"cpe": "cpe:2.3:a:squid-cache:squid:3.4.0.4:*:*:*:*:*:*:*",
"source": "CPE_FIELD"
},
{
"extracted_events": [
{
"last_affected": "8.0"
}
],
"cpe": "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*",
"source": "CPE_FIELD"
}
]
}{
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "3.1.10"
},
{
"last_affected": "3.1.11"
},
{
"last_affected": "3.1.12"
},
{
"last_affected": "3.1.14"
},
{
"last_affected": "3.1.15"
},
{
"last_affected": "3.1.16"
},
{
"last_affected": "3.1.17"
},
{
"last_affected": "3.1.18"
},
{
"last_affected": "3.1.19"
},
{
"last_affected": "3.1.20"
},
{
"last_affected": "3.1.21"
},
{
"last_affected": "3.1.22"
},
{
"last_affected": "3.1.23"
},
{
"last_affected": "3.2.0.3"
},
{
"last_affected": "3.2.0.4"
},
{
"last_affected": "3.2.0.5"
},
{
"last_affected": "3.2.0.6"
},
{
"last_affected": "3.2.0.7"
},
{
"last_affected": "3.2.0.8"
},
{
"last_affected": "3.2.0.9"
},
{
"last_affected": "3.2.0.10"
},
{
"last_affected": "3.2.0.11"
},
{
"last_affected": "3.2.0.12"
},
{
"last_affected": "3.2.0.13"
},
{
"last_affected": "3.2.0.14"
},
{
"last_affected": "3.2.0.15"
},
{
"last_affected": "3.2.0.16"
},
{
"last_affected": "3.2.0.17"
},
{
"last_affected": "3.2.0.18"
},
{
"last_affected": "3.2.0.19"
},
{
"last_affected": "3.2.1"
},
{
"last_affected": "3.2.2"
},
{
"last_affected": "3.2.3"
},
{
"last_affected": "3.2.4"
},
{
"last_affected": "3.2.5"
},
{
"last_affected": "3.2.6"
},
{
"last_affected": "3.2.7"
},
{
"last_affected": "3.2.8"
},
{
"last_affected": "3.2.9"
},
{
"last_affected": "3.2.10"
},
{
"last_affected": "3.2.11"
},
{
"last_affected": "3.2.12"
},
{
"last_affected": "3.2.13"
},
{
"last_affected": "3.2.14"
},
{
"last_affected": "3.3.0.1"
},
{
"last_affected": "3.3.0.2"
},
{
"last_affected": "3.3.0.3"
},
{
"last_affected": "3.3.1"
},
{
"last_affected": "3.3.2"
},
{
"last_affected": "3.3.3"
},
{
"last_affected": "3.3.4"
},
{
"last_affected": "3.3.5"
},
{
"last_affected": "3.3.6"
},
{
"last_affected": "3.3.7"
},
{
"last_affected": "3.3.8"
},
{
"last_affected": "3.3.9"
},
{
"last_affected": "3.3.10"
},
{
"last_affected": "3.3.11"
},
{
"last_affected": "3.3.12"
},
{
"last_affected": "3.3.13"
},
{
"last_affected": "3.3.14"
},
{
"last_affected": "3.4.0.1"
},
{
"last_affected": "3.4.0.2"
},
{
"last_affected": "3.4.0.3"
},
{
"last_affected": "3.4.1"
},
{
"last_affected": "3.4.2"
},
{
"last_affected": "3.4.3"
},
{
"last_affected": "3.4.4"
},
{
"last_affected": "3.4.5"
},
{
"last_affected": "3.4.6"
},
{
"last_affected": "3.4.7"
},
{
"last_affected": "3.4.8"
},
{
"last_affected": "3.4.9"
},
{
"last_affected": "3.4.10"
},
{
"last_affected": "3.4.11"
},
{
"last_affected": "3.4.12"
},
{
"last_affected": "3.4.13"
},
{
"last_affected": "3.4.14"
},
{
"last_affected": "3.5.0.1"
},
{
"last_affected": "3.5.0.2"
},
{
"last_affected": "3.5.0.3"
},
{
"last_affected": "3.5.0.4"
},
{
"last_affected": "3.5.1"
},
{
"last_affected": "3.5.2"
},
{
"last_affected": "3.5.3"
},
{
"last_affected": "3.5.4"
},
{
"last_affected": "3.5.5"
},
{
"last_affected": "3.5.6"
},
{
"last_affected": "3.5.7"
},
{
"last_affected": "3.5.8"
},
{
"last_affected": "3.5.9"
},
{
"last_affected": "3.5.10"
},
{
"last_affected": "3.5.11"
},
{
"last_affected": "3.5.12"
},
{
"last_affected": "3.5.13"
},
{
"last_affected": "3.5.14"
},
{
"last_affected": "3.5.15"
},
{
"last_affected": "3.5.16"
},
{
"last_affected": "3.5.17"
},
{
"last_affected": "3.5.18"
},
{
"last_affected": "3.5.19"
},
{
"last_affected": "3.5.20"
},
{
"last_affected": "3.5.21"
},
{
"last_affected": "3.5.22"
},
{
"last_affected": "4.0.1"
},
{
"last_affected": "4.0.2"
},
{
"last_affected": "4.0.3"
},
{
"last_affected": "4.0.4"
},
{
"last_affected": "4.0.5"
},
{
"last_affected": "4.0.6"
},
{
"last_affected": "4.0.7"
},
{
"last_affected": "4.0.8"
},
{
"last_affected": "4.0.9"
},
{
"last_affected": "4.0.10"
},
{
"last_affected": "4.0.11"
},
{
"last_affected": "4.0.12"
},
{
"last_affected": "4.0.13"
},
{
"last_affected": "4.0.14"
},
{
"last_affected": "4.0.15"
},
{
"last_affected": "4.0.16"
}
],
"cpe": [
"cpe:2.3:a:squid-cache:squid:3.1.10:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.11:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.12:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.14:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.15:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.16:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.17:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.18:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.19:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.20:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.21:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.22:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.1.23:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.0.3:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.0.4:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.0.5:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.0.6:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.0.7:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.0.8:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.0.9:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.0.10:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.0.11:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.0.12:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.0.13:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.0.14:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.0.15:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.0.16:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.0.17:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.0.18:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.0.19:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.1:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.2:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.3:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.4:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.5:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.6:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.7:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.8:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.9:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.10:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.11:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.12:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.13:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.2.14:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.3.0.1:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.3.0.2:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.3.0.3:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.3.1:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.3.2:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.3.3:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.3.4:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.3.5:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.3.6:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.3.7:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.3.8:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.3.9:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.3.10:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.3.11:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.3.12:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.3.13:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.3.14:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.4.0.1:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.4.0.2:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.4.0.3:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.4.1:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.4.2:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.4.3:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.4.4:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.4.5:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.4.6:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.4.7:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.4.8:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.4.9:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.4.10:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.4.11:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.4.12:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.4.13:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.4.14:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.5.0.1:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.5.0.2:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.5.0.3:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.5.0.4:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.5.1:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.5.2:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.5.3:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.5.4:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.5.5:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.5.6:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.5.7:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.5.8:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.5.9:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.5.10:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.5.11:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.5.12:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.5.13:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.5.14:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.5.15:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.5.16:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.5.17:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.5.18:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.5.19:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.5.20:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.5.21:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:3.5.22:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:4.0.1:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:4.0.2:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:4.0.3:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:4.0.4:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:4.0.5:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:4.0.6:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:4.0.7:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:4.0.8:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:4.0.9:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:4.0.10:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:4.0.11:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:4.0.12:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:4.0.13:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:4.0.14:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:4.0.15:*:*:*:*:*:*:*",
"cpe:2.3:a:squid-cache:squid:4.0.16:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD"
}