V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2015-0881
DEB
Medium

CRLF injection vulnerability in Squid before 3.1.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response split…

CVSS
4.3
Medium
EPSS
0.05
p90
Published
2015-01-01
Updated
2015-01-01
Description

CRLF injection vulnerability in Squid before 3.1.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted header in a response.

Tags · CWE
CWE-113
CAPEC-31
CAPEC-34
CAPEC-85
CAPEC-105
Affected products
Squid ≤ 3.1.0.18
CVSS vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Timeline
2015-01-01
Published
2015-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: M
Medium
Authentication
Au: N
None (N)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: P
Partial
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.045 · p90
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-31 · CWE-113
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
squidTracked
squidTracked
squidTracked
squid3Tracked
squid3Tracked
squid3Tracked
squid*Tracked
Source databases
DEB
CVE
UBU