PT-2005-1262 · Squid+1 · Squid+2

Published

2005-02-06

·

Updated

2017-10-11

·

CVE-2005-0174

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Squid versions 2.5 up to 2.5.STABLE7
Description The issue allows remote attackers to poison the cache or conduct certain attacks via headers that do not follow the HTTP specification. This includes multiple Content-Length headers, carriage return (CR) characters that are not part of a CRLF pair, and header names containing whitespace characters.
Recommendations For Squid versions 2.5 up to 2.5.STABLE7, consider updating to a version that properly handles non-standard HTTP headers to prevent cache poisoning and other attacks. As a temporary workaround, restrict access to the Squid cache to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-0174
RHSA-2005:060
RHSA-2005:061
RHSA-2005_060
RHSA-2005_061

Affected Products

Red Hat
Squid
Squid Cache