Vulnerability Description
Squid 3.1.9 allows remote attackers to bypass the access configuration for the CONNECT method by providing an arbitrary allowed hostname in the Host HTTP header. NOTE: this issue might not be reproducible, because the researcher is unable to provide a squid.conf file for a vulnerable system, and the observed behavior is consistent with a squid.conf file that was (perhaps inadvertently) designed to allow access based on a "req_header Host" acl regex that matches www.uol.com.br
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Squid-Cache | Squid | 3.1.9 |
Related Weaknesses (CWE)
References
- http://archives.neohapsis.com/archives/bugtraq/2012-04/0117.html
- http://archives.neohapsis.com/archives/bugtraq/2012-04/0131.html
- http://archives.neohapsis.com/archives/bugtraq/2012-04/0140.html
- http://archives.neohapsis.com/archives/bugtraq/2012-04/0146.html
- http://archives.neohapsis.com/archives/bugtraq/2012-04/0163.html
- http://archives.neohapsis.com/archives/bugtraq/2012-04/0165.html
- http://archives.neohapsis.com/archives/bugtraq/2012-04/0117.html
- http://archives.neohapsis.com/archives/bugtraq/2012-04/0131.html
- http://archives.neohapsis.com/archives/bugtraq/2012-04/0140.html
- http://archives.neohapsis.com/archives/bugtraq/2012-04/0146.html
- http://archives.neohapsis.com/archives/bugtraq/2012-04/0163.html
- http://archives.neohapsis.com/archives/bugtraq/2012-04/0165.html
FAQ
What is CVE-2012-2213?
CVE-2012-2213 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Squid 3.1.9 allows remote attackers to bypass the access configuration for the CONNECT method by providing an arbitrary allowed hostname in the Host HTTP header. NOTE: this issue might not be reprodu...
How severe is CVE-2012-2213?
CVE-2012-2213 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-2213?
Check the references section above for vendor advisories and patch information. Affected products include: Squid-Cache Squid.