CVE-2016-10002

Publication date 27 January 2017

Last updated 24 July 2024


Ubuntu priority

Cvss 3 Severity Score

7.5 · High

Score breakdown

Incorrect processing of responses to If-None-Modified HTTP conditional requests in Squid HTTP Proxy 3.1.10 through 3.1.23, 3.2.0.3 through 3.5.22, and 4.0.1 through 4.0.16 leads to client-specific Cookie data being leaked to other clients. Attack requests can easily be crafted by a client to probe a cache for this information.

Status

Package Ubuntu Release Status
squid3 16.10 yakkety
Fixed 3.5.12-1ubuntu8.1
16.04 LTS xenial
Fixed 3.5.12-1ubuntu7.3
14.04 LTS trusty
Fixed 3.3.8-1ubuntu6.9
12.04 LTS precise
Fixed 3.1.19-1ubuntu3.12.04.8

Severity score breakdown

Parameter Value
Base score 7.5 · High
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Scope Unchanged
Confidentiality High
Integrity impact None
Availability impact None
Vector CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N