PT-2005-1262 · Squid+1 · Squid+2

Publicado

2005-02-06

·

Atualizado

2017-10-11

·

CVE-2005-0174

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Squid versions 2.5 up to 2.5.STABLE7
Description The issue allows remote attackers to poison the cache or conduct certain attacks via headers that do not follow the HTTP specification. This includes multiple Content-Length headers, carriage return (CR) characters that are not part of a CRLF pair, and header names containing whitespace characters.
Recommendations For Squid versions 2.5 up to 2.5.STABLE7, consider updating to a version that properly handles non-standard HTTP headers to prevent cache poisoning and other attacks. As a temporary workaround, restrict access to the Squid cache to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-0174
RHSA-2005:060
RHSA-2005:061
RHSA-2005_060
RHSA-2005_061

Produtos afetados

Red Hat
Squid
Squid Cache