Squid 2.4 STABLE3 and earlier does not properly disable HTCP, even when "htcp_port 0" is specified in squid.conf, which could allow remote attackers to bypass intended access restrictions.
| Software | From | Fixed in |
|---|---|---|
| squid / squid | - | 2.4_stable_2.x |
| redhat / linux | 7.2 | 7.2.x |
| redhat / linux | 6.2 | 6.2.x |
| redhat / linux | 7.1 | 7.1.x |
| redhat / linux | 7.0 | 7.0.x |