Candidate: CVE-2014-9749 PublicDate: 2015-11-06 21:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9749 http://bugs.squid-cache.org/show_bug.cgi?id=4066 http://bazaar.launchpad.net/~squid/squid/3.4/revision/13211 (Squid 3.4) http://bazaar.launchpad.net/~squid/squid/3.5/revision/13735 (Squid 3.5) Description: Squid 3.4.4 through 3.4.11 and 3.5.0.1 through 3.5.1, when Digest authentication is used, allow remote authenticated users to retain access by leveraging a stale nonce, aka "Nonce replay vulnerability." Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=776464 Priority: low Discovered-by: Assigned-to: CVSS: Patches_squid3: upstream_squid3: released (3.5.2) precise_squid3: not-affected trusty_squid3: not-affected trusty/esm_squid3: DNE (trusty was not-affected) vivid_squid3: not-affected wily_squid3: not-affected devel_squid3: not-affected (3.3.8-1ubuntu16)