Lucene search

K
mageiaGentoo FoundationMGASA-2015-0191
HistoryMay 05, 2015 - 4:36 p.m.

Updated squid packages fix CVE-2015-3455

2015-05-0516:36:50
Gentoo Foundation
advisories.mageia.org
24

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

EPSS

0.017

Percentile

87.7%

Updated squid packages fix security vulnerability: Squid configured with client-first SSL-bump does not correctly validate X509 server certificate domain / hostname fields (CVE-2015-3455).

OSVersionArchitecturePackageVersionFilename
Mageia4noarchsquid< 3.3.14-1squid-3.3.14-1.mga4

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

EPSS

0.017

Percentile

87.7%