Vulnerability Bulletins |
DSA-3745 squid3 - security update |
|
| Affected software | Debian |
|
Saulius Lapinskas from Lithuanian State Social Insurance Fund Boarddiscovered that Squid3, a fully featured web proxy cache, does notproperly process responses to If-None-Modified HTTP conditionalrequests, leading to client-specific Cookie data being leaked to otherclients. A remote attacker can take advantage of this flaw to discoverprivate and sensitive information about another clients browsingsession. More info: https://www.debian.org/security/2016/dsa-3745 |
|






