PT-2005-1261 · Squid+1 · Squid+2

Henrik Nordstrom

·

Publicado

2005-02-06

·

Atualizado

2017-10-11

·

CVE-2005-0173

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Squid versions 2.5 and earlier
Description The issue allows remote authenticated users to bypass username-based Access Control Lists (ACLs) by using a username with a space at the beginning or end. This is possible because the LDAP server ignores such spaces in usernames.
Recommendations For Squid versions 2.5 and earlier, consider updating to a version where this issue is fixed, or as a temporary workaround, restrict the use of usernames with leading or trailing spaces to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-0173
DSA-667-1
RHSA-2005:060
RHSA-2005:061
RHSA-2005_060
RHSA-2005_061

Produtos afetados

Red Hat
Squid
Squid Cache