Back to search
CVE-2005-0241
Published: Feb 8, 2005
Modified: Aug 7, 2024
PUBLISHED
Description
The httpProcessReplyHeader function in http.c for Squid 2.5-STABLE7 and earlier does not properly set the debug context when it is handling "oversized" HTTP reply headers, which might allow remote attackers to poison the cache or bypass access controls based on header size.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
14091
third-party-advisory
x_refsource_SECUNIA
VU#823350
third-party-advisory
x_refsource_CERT-VN
12412
vdb-entry
x_refsource_BID
http://www.squid-cache.org/bugs/show_bug.cgi?id=1216
x_refsource_CONFIRM
oval:org.mitre.oval:def:10998
vdb-entry
signature
x_refsource_OVAL
FLSA-2006:152809
vendor-advisory
x_refsource_FEDORA
RHSA-2005:061
vendor-advisory
x_refsource_REDHAT
squid-http-cache-poisoning(19060)
vdb-entry
x_refsource_XF
CLA-2005:931
vendor-advisory
x_refsource_CONECTIVA
SUSE-SA:2005:006
vendor-advisory
x_refsource_SUSE
RHSA-2005:060
vendor-advisory
x_refsource_REDHAT
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now