PT-2005-1261 · Squid+1 · Squid+2

Henrik Nordstrom

·

Published

2005-02-06

·

Updated

2017-10-11

·

CVE-2005-0173

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Squid versions 2.5 and earlier
Description The issue allows remote authenticated users to bypass username-based Access Control Lists (ACLs) by using a username with a space at the beginning or end. This is possible because the LDAP server ignores such spaces in usernames.
Recommendations For Squid versions 2.5 and earlier, consider updating to a version where this issue is fixed, or as a temporary workaround, restrict the use of usernames with leading or trailing spaces to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-0173
DSA-667-1
RHSA-2005:060
RHSA-2005:061
RHSA-2005_060
RHSA-2005_061

Affected Products

Red Hat
Squid
Squid Cache