CVE-2016-4553

CVE-2016-4553

Published · Updated

25Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 80%
exploitation probability
80%top 1% of all CVEs
observed exploitation
nono source reports it
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Fixed
6 products (70 components)
Red Hat Enterprise Linux Server (v. 7) · Red Hat Enterprise Linux Server Optional (v. 7) · Red Hat Enterprise Linux Workstation (v. 7) · Red Hat Enterprise Linux Workstation Optional (v. 7) · Red Hat Enterprise Linux Server (v. 6) · and others 1
Not affected
2 products (3 components) — because the vulnerable code is not present in the product
Red Hat Enterprise Linux 6 · Red Hat Enterprise Linux 5
client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which allows remote attackers to conduct cache-poisoning attacks via an HTTP request.
Affected products
n/a · n/a