CVE-2015-3455
EPSS 11.4%
描述
Squid 3.2.x before 3.2.14, 3.3.x before 3.3.14, 3.4.x before 3.4.13, and 3.5.x before 3.5.4, when configured with client-first SSL-bump, do not properly validate the domain or hostname fields of X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate.
如何修補 CVE-2015-3455
要修補 CVE-2015-3455,請將受影響套件升級到下列已修補版本。
- Debian/squid—升級至 4.1-1 或更新版本
CVE-2015-3455 正在被利用嗎?
中等 — EPSS 為 11.4%,可持續追蹤但非最高優先。
受影響套件(1)
- from 0, < 4.1-1