|
|
Log in / Subscribe / Register

squid: certificate validation bypass

Package(s):squid CVE #(s):CVE-2015-3455
Created:May 4, 2015 Updated:December 22, 2015
Description: From the Arch Linux advisory:

The flaw allows remote servers to bypass client certificate validation. Some attackers may also be able to use valid certificates for one domain signed by a global Certificate Authority to abuse an unrelated domain. However, the bug is exploitable only if you have configured Squid to perform SSL Bumping with the "client-first" or "bump" mode of operation. Sites that do not use SSL-Bump are not vulnerable.

A remote attacker is able to bypass client certificate validation, as a result malicious server responses can wrongly be presented through the proxy to clients as secure authenticated HTTPS responses.

Alerts:
openSUSE openSUSE-SU-2016:2081-1 squid 2016-08-16
Scientific Linux SLSA-2015:2378-1 squid 2015-12-21
Fedora FEDORA-2016-7b40eb9e29 squid 2016-05-06
Fedora FEDORA-2016-7b40eb9e29 libecap 2016-05-06
Oracle ELSA-2015-2378 squid 2015-11-23
Red Hat RHSA-2015:2378-01 squid 2015-11-19
openSUSE openSUSE-SU-2015:1546-1 squid 2015-09-11
Mandriva MDVSA-2015:230 squid 2015-05-06
Mageia MGASA-2015-0191 squid 2015-05-05
Arch Linux ASA-201505-1 squid 2015-05-02

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds