PT-2005-1292 · Squid+1 · Squid+2
Published
2005-02-06
·
Updated
2018-10-12
·
CVE-2005-0211
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Squid versions prior to 2.5.STABLE7
Squid version 2.5 before 2.5.STABLE7
Description
A buffer overflow issue exists due to a long WCCP packet being processed by a recvfrom function call with an incorrect length parameter in the wccp.c file. This can cause a denial of service and potentially allow remote attackers to execute arbitrary code.
Recommendations
For Squid versions prior to 2.5.STABLE7, update to version 2.5.STABLE7 or later to resolve the issue.
For Squid version 2.5 before 2.5.STABLE7, update to version 2.5.STABLE7 or later to resolve the issue.
Fix
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Red Hat
Squid
Squid Cache