Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Squid 3.2.x before 3.2.14, 3.3.x before 3.3.14, 3.4.x before 3.4.13, and 3.5.x before 3.5.4, when configured with client-first SSL-bump, do not properly validate the domain or hostname fields of X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Squid Certificate Validation 安全漏洞
Vulnerability Description
Squid(全称Squid Cache)是一套代理服务器和Web缓存服务器软件。该软件提供缓存万维网、过滤流量、代理上网等功能。 Squid中存在安全漏洞,该漏洞源于程序配置了client-first SSL-bump时,没有正确验证X.509证书的‘domain’或‘hostname’字段。攻击者可借助特制的证书利用该漏洞实施中间人攻击,欺骗服务器。以下版本受到影响:Squid 3.2.14之前3.2.x版本,3.3.14之前3.3.x版本,3.4.13之前3.4.x版本,3.5.4之前3.5.x版本。
CVSS Information
N/A
Vulnerability Type
N/A