Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2005-0174
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2005-0174

Description:
Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache or conduct certain attacks via headers that do not follow the HTTP specification, including (1) multiple Content-Length headers, (2) carriage return (CR) characters that are not part of a CRLF pair, and (3) header names containing whitespace characters.

CVE Status:
Candidate

References:

SUSE
  http://www.novell.com/linux/security/advisories/2005_06_squid.html

REDHAT
  http://www.redhat.com/support/errata/RHSA-2005-060.html
  http://www.redhat.com/support/errata/RHSA-2005-061.html

MANDRAKE
  http://www.mandrakesoft.com/security/advisories?name=MDKSA-2005:034

FEDORA
  http://www.redhat.com/archives/fedora-announce-list/2005-May/msg00025.html
  http://fedoranews.org/updates/FEDORA--.shtml

CONFIRM
  http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-header_parsing
  http://www3.br.squid-cache.org/Advisories/SQUID-2005_4.txt

CONECTIVA
  http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000931

CERT-VN
  768702

BUGTRAQ
  http://marc.theaimsgroup.com/?l=bugtraq&m=110780531820947&w=2

BID
  12412


Return to the previous page.