CVE-2005-0241

The httpProcessReplyHeader function in http.c for Squid 2.5-STABLE7 and earlier does not properly set the debug context when it is handling "oversized" HTTP reply headers, which might allow remote attackers to poison the cache or bypass access controls based on header size.
References
Link Resource
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000931 Patch
http://fedoranews.org/updates/FEDORA--.shtml
http://secunia.com/advisories/14091
http://www.kb.cert.org/vuls/id/823350 Patch Third Party Advisory US Government Resource
http://www.novell.com/linux/security/advisories/2005_06_squid.html Patch Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2005-060.html Patch Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2005-061.html Patch Vendor Advisory
http://www.securityfocus.com/bid/12412
http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-oversize_reply_headers Patch
http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-oversize_reply_headers.patch Patch
http://www.squid-cache.org/bugs/show_bug.cgi?id=1216 Patch
https://exchange.xforce.ibmcloud.com/vulnerabilities/19060
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10998
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000931 Patch
http://fedoranews.org/updates/FEDORA--.shtml
http://secunia.com/advisories/14091
http://www.kb.cert.org/vuls/id/823350 Patch Third Party Advisory US Government Resource
http://www.novell.com/linux/security/advisories/2005_06_squid.html Patch Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2005-060.html Patch Vendor Advisory
http://www.redhat.com/support/errata/RHSA-2005-061.html Patch Vendor Advisory
http://www.securityfocus.com/bid/12412
http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-oversize_reply_headers Patch
http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-oversize_reply_headers.patch Patch
http://www.squid-cache.org/bugs/show_bug.cgi?id=1216 Patch
https://exchange.xforce.ibmcloud.com/vulnerabilities/19060
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10998
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:squid:squid:2.5.stable1:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.5.stable2:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.5.stable3:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.5.stable4:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.5.stable5:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.5.stable6:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.5.stable7:*:*:*:*:*:*:*

History

20 Nov 2024, 23:54

Type Values Removed Values Added
References () http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000931 - Patch () http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000931 - Patch
References () http://fedoranews.org/updates/FEDORA--.shtml - () http://fedoranews.org/updates/FEDORA--.shtml -
References () http://secunia.com/advisories/14091 - () http://secunia.com/advisories/14091 -
References () http://www.kb.cert.org/vuls/id/823350 - Patch, Third Party Advisory, US Government Resource () http://www.kb.cert.org/vuls/id/823350 - Patch, Third Party Advisory, US Government Resource
References () http://www.novell.com/linux/security/advisories/2005_06_squid.html - Patch, Vendor Advisory () http://www.novell.com/linux/security/advisories/2005_06_squid.html - Patch, Vendor Advisory
References () http://www.redhat.com/support/errata/RHSA-2005-060.html - Patch, Vendor Advisory () http://www.redhat.com/support/errata/RHSA-2005-060.html - Patch, Vendor Advisory
References () http://www.redhat.com/support/errata/RHSA-2005-061.html - Patch, Vendor Advisory () http://www.redhat.com/support/errata/RHSA-2005-061.html - Patch, Vendor Advisory
References () http://www.securityfocus.com/bid/12412 - () http://www.securityfocus.com/bid/12412 -
References () http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-oversize_reply_headers - Patch () http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-oversize_reply_headers - Patch
References () http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-oversize_reply_headers.patch - Patch () http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-oversize_reply_headers.patch - Patch
References () http://www.squid-cache.org/bugs/show_bug.cgi?id=1216 - Patch () http://www.squid-cache.org/bugs/show_bug.cgi?id=1216 - Patch
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/19060 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/19060 -
References () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10998 - () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10998 -

Information

Published : 2005-05-02 04:00

Updated : 2024-11-20 23:54


NVD link : CVE-2005-0241

Mitre link : CVE-2005-0241

CVE.ORG link : CVE-2005-0241


JSON object : View

Products Affected

squid

  • squid