2.6
CVSSv2

CVE-2015-3455

Published: 18/05/2015 Updated: 27/12/2019
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

Squid 3.2.x prior to 3.2.14, 3.3.x prior to 3.3.14, 3.4.x prior to 3.4.13, and 3.5.x prior to 3.5.4, when configured with client-first SSL-bump, do not properly validate the domain or hostname fields of X.509 certificates, which allows man-in-the-middle malicious users to spoof SSL servers via a valid certificate.

Vulnerable Product Search on Vulmon Subscribe to Product

oracle solaris 11.2

oracle linux 7

squid-cache squid 3.2.0.15

squid-cache squid 3.2.0.16

squid-cache squid 3.2.0.5

squid-cache squid 3.2.0.6

squid-cache squid 3.2.13

squid-cache squid 3.2.2

squid-cache squid 3.2.9

squid-cache squid 3.3.9

squid-cache squid 3.3.2

squid-cache squid 3.3.0

squid-cache squid 3.3.0.1

squid-cache squid 3.4.0.1

squid-cache squid 3.4.5

squid-cache squid 3.4.6

squid-cache squid 3.5.0.1

squid-cache squid 3.5.0.2

squid-cache squid 3.2.0.11

squid-cache squid 3.2.0.12

squid-cache squid 3.2.0.19

squid-cache squid 3.2.0.2

squid-cache squid 3.2.0.9

squid-cache squid 3.2.1

squid-cache squid 3.2.10

squid-cache squid 3.2.5

squid-cache squid 3.2.6

squid-cache squid 3.3.6

squid-cache squid 3.3.5

squid-cache squid 3.3.10

squid-cache squid 3.3.1

squid-cache squid 3.4.1

squid-cache squid 3.4.2

squid-cache squid 3.4.9

squid-cache squid 3.4.10

squid-cache squid 3.5.2

squid-cache squid 3.2.0.13

squid-cache squid 3.2.0.14

squid-cache squid 3.2.0.3

squid-cache squid 3.2.0.4

squid-cache squid 3.2.11

squid-cache squid 3.2.12

squid-cache squid 3.2.7

squid-cache squid 3.2.8

squid-cache squid 3.3.4

squid-cache squid 3.3.3

squid-cache squid 3.3.0.3

squid-cache squid 3.3.0.2

squid-cache squid 3.4.3

squid-cache squid 3.4.4

squid-cache squid 3.4.11

squid-cache squid 3.4.12

squid-cache squid 3.2.0.1

squid-cache squid 3.2.0.10

squid-cache squid 3.2.0.17

squid-cache squid 3.2.0.18

squid-cache squid 3.2.0.7

squid-cache squid 3.2.0.8

squid-cache squid 3.2.3

squid-cache squid 3.2.4

squid-cache squid 3.3.8

squid-cache squid 3.3.7

squid-cache squid 3.3.12

squid-cache squid 3.3.13

squid-cache squid 3.3.11

squid-cache squid 3.4.0.2

squid-cache squid 3.4.0.3

squid-cache squid 3.4.7

squid-cache squid 3.4.8

squid-cache squid 3.5.0.3

squid-cache squid 3.5.0.4

squid-cache squid 3.5.1

fedoraproject fedora 22

Vendor Advisories

It was found that Squid configured with client-first SSL-bump did not correctly validate X509 server certificate host name fields A man-in-the-middle attacker could use this flaw to spoof a Squid server using a specially crafted X509 certificate ...