Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2005-0194
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2005-0194

Description:
Squid 2.5, when processing the configuration file, parses empty Access Control Lists (ACLs), including proxy_auth ACLs without defined auth schemes, in a way that effectively removes arguments, which could allow remote attackers to bypass intended ACLs if the administrator ignores the parser warnings.

CVE Status:
Candidate

References:

FEDORA
  http://fedoranews.org/updates/FEDORA--.shtml

DEBIAN
  http://www.debian.org/security/2005/dsa-667

CONFIRM
  http://www.squid-cache.org/bugs/show_bug.cgi?id=1166
  http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-empty_acls
  http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-empty_acls.patch

CONECTIVA
  http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000923

CERT-VN
  260421

BUGTRAQ
  http://marc.theaimsgroup.com/?l=bugtraq&m=110901183320453&w=2


Return to the previous page.