Fedora Account System
Red Hat Associate
Red Hat Customer
A request smuggling vulnerability was found in Squid. Due to improper enforcement of behavioral workflow when processing HTTP/1.1 Transfer-Encoding headers, a trusted client can perform an HTTP request smuggling attack. This can bypass security mechanisms between the attacker and Squid. When an HTTP cache operates prior to the affected Squid instance, this also allows cache poisoning, enabling the attacker to store arbitrary malicious content at any URL for delivery to other clients. Squid versions 3.3.0.1 through 7.5 are affected. The fix is available in version 7.6.