CVE-2016-10003: Infoleak
Incorrect HTTP Request header comparison in Squid HTTP Proxy 3.5.0.1 through 3.5.22, and 4.0.1 through 4.0.16 results in Collapsed Forwarding feature mistakenly identifying some private responses as being suitable for delivery to multiple clients.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-10003?
CVE-2016-10003 is classified as a moderate severity vulnerability due to its potential impact on data privacy.
How do I fix CVE-2016-10003?
To fix CVE-2016-10003, upgrade Squid HTTP Proxy to version 3.5.23 or newer, or 4.0.17 or newer.
What software versions are affected by CVE-2016-10003?
CVE-2016-10003 affects Squid HTTP Proxy versions from 3.5.0.1 to 3.5.22 and 4.0.1 to 4.0.16.
Is CVE-2016-10003 easy to exploit?
Exploitation of CVE-2016-10003 may require a specific configuration, but could lead to unintended data exposure.
What are the implications of CVE-2016-10003?
CVE-2016-10003 can result in private responses being delivered to multiple clients, compromising confidentiality.