CVE-2015-0881

Publication date 20 February 2015

Last updated 24 July 2024


Ubuntu priority

CRLF injection vulnerability in Squid before 3.1.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted header in a response.

Status

Package Ubuntu Release Status
squid 14.10 utopic Not in release
14.04 LTS trusty Not in release
12.04 LTS precise Not in release
10.04 LTS lucid Ignored end of life
squid3 14.10 utopic
Not affected
14.04 LTS trusty Not in release
12.04 LTS precise
Not affected
10.04 LTS lucid Ignored end of life