PT-2005-1277 · Squid · Squid+1

Publicado

2005-02-06

·

Atualizado

2016-10-18

·

CVE-2005-0194

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Squid version 2.5
Description The issue arises when Squid processes its configuration file, specifically with empty Access Control Lists (ACLs), including proxy auth ACLs that lack defined authentication schemes. This parsing behavior can remove arguments, potentially allowing remote attackers to bypass intended ACLs if the administrator disregards parser warnings.
Recommendations For Squid version 2.5, ensure that all Access Control Lists (ACLs), especially proxy auth ACLs, have defined authentication schemes to prevent the removal of arguments during configuration file processing. Define proper auth schemes for proxy auth ACLs to maintain the integrity of intended ACLs.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-0194
DSA-667-1

Produtos afetados

Squid
Squid Cache