PT-2005-1261 · Squid+1 · Squid+2
Henrik Nordstrom
·
Published
2005-02-06
·
Updated
2017-10-11
·
CVE-2005-0173
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Squid versions 2.5 and earlier
Description
The issue allows remote authenticated users to bypass username-based Access Control Lists (ACLs) by using a username with a space at the beginning or end. This is possible because the LDAP server ignores such spaces in usernames.
Recommendations
For Squid versions 2.5 and earlier, consider updating to a version where this issue is fixed, or as a temporary workaround, restrict the use of usernames with leading or trailing spaces to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Red Hat
Squid
Squid Cache