PT-2005-1277 · Squid · Squid+1
Publicado
2005-02-06
·
Atualizado
2016-10-18
·
CVE-2005-0194
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Squid version 2.5
Description
The issue arises when Squid processes its configuration file, specifically with empty Access Control Lists (ACLs), including proxy auth ACLs that lack defined authentication schemes. This parsing behavior can remove arguments, potentially allowing remote attackers to bypass intended ACLs if the administrator disregards parser warnings.
Recommendations
For Squid version 2.5, ensure that all Access Control Lists (ACLs), especially proxy auth ACLs, have defined authentication schemes to prevent the removal of arguments during configuration file processing. Define proper auth schemes for proxy auth ACLs to maintain the integrity of intended ACLs.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Squid
Squid Cache