← Back

CVE-2015-3455

nvd nist
Published: May 18, 2015Modified: May 6, 2026

JSON object

Loading...
2.6
Vector
AV:N/AC:H/Au:N/C:N/I:P/A:N
Exploitability: 4.9 / Impact: 2.9
Source: NVD

Description

Squid 3.2.x before 3.2.14, 3.3.x before 3.3.14, 3.4.x before 3.4.13, and 3.5.x before 3.5.4, when configured with client-first SSL-bump, do not properly validate the domain or hostname fields of X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate.

Affected (73)

2 products
Linux
Solaris
1 product
Squid
1 product
Fedora
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Version 7
Version 11.2
Configuration B
70 vulnerable
Vulnerable SoftwareAffected Versions
Squid Cache
Version 3.2.0.10
Version 3.2.0.11
Version 3.2.0.12
Version 3.2.0.13
Version 3.2.0.14
Version 3.2.0.15
Version 3.2.0.16
Version 3.2.0.17
Version 3.2.0.18
Version 3.2.0.19
Version 3.2.0.1
Version 3.2.0.2
Version 3.2.0.3
Version 3.2.0.4
Version 3.2.0.5
Version 3.2.0.6
Version 3.2.0.7
Version 3.2.0.8
Version 3.2.0.9
Version 3.2.10
Version 3.2.11
Version 3.2.12
Version 3.2.13
Version 3.2.1
Version 3.2.2
Version 3.2.3
Version 3.2.4
Version 3.2.5
Version 3.2.6
Version 3.2.7
Version 3.2.8
Version 3.2.9
Version 3.3.0.1
Version 3.3.0.2
Version 3.3.0.3
Version 3.3.0
Version 3.3.10
Version 3.3.11
Version 3.3.12
Version 3.3.13
Version 3.3.1
Version 3.3.2
Version 3.3.3
Version 3.3.4
Version 3.3.5
Version 3.3.6
Version 3.3.7
Version 3.3.8
Version 3.3.9
Version 3.4.0.1
Version 3.4.0.2
Version 3.4.0.3
Version 3.4.10
Version 3.4.11
Version 3.4.12
Version 3.4.1
Version 3.4.2
Version 3.4.3
Version 3.4.4
Version 3.4.5
Version 3.4.6
Version 3.4.7
Version 3.4.8
Version 3.4.9
Version 3.5.0.1
Version 3.5.0.2
Version 3.5.0.3
Version 3.5.0.4
Version 3.5.1
Version 3.5.2
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 22

References (22)

Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.