Squid Proxy Set-Cookie Headers Information Disclosure Vulnerability
BID:12716
Info
Squid Proxy Set-Cookie Headers Information Disclosure Vulnerability
| Bugtraq ID: | 12716 |
| Class: | Race Condition Error |
| CVE: |
CVE-2005-0626 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 03 2005 12:00AM |
| Updated: | Mar 07 2007 05:25AM |
| Credit: | This issue was reported by the vendor. |
| Vulnerable: |
Ubuntu Ubuntu Linux 4.1 ppc Ubuntu Ubuntu Linux 4.1 ia64 Ubuntu Ubuntu Linux 4.1 ia32 Turbolinux Turbolinux Workstation 8.0 Turbolinux Turbolinux Workstation 7.0 Turbolinux Turbolinux Server 10.0 Turbolinux Turbolinux Server 8.0 Turbolinux Turbolinux Server 7.0 Turbolinux Appliance Server Workgroup Edition 1.0 Turbolinux Appliance Server Hosting Edition 1.0 Squid Web Proxy Cache 2.5 .STABLE9 Squid Web Proxy Cache 2.5 .STABLE8 Squid Web Proxy Cache 2.5 .STABLE7 SGI ProPack 3.0 SP5 Redhat Linux 9.0 i386 Redhat Linux 7.3 i386 Redhat Fedora Core3 Redhat Fedora Core2 Redhat Fedora Core1 Redhat Enterprise Linux WS 4 Redhat Enterprise Linux WS 3 Redhat Enterprise Linux ES 4 Redhat Enterprise Linux ES 3 Redhat Enterprise Linux AS 4 Redhat Enterprise Linux AS 3 Redhat Desktop 4.0 Redhat Desktop 3.0 |
| Not Vulnerable: | |
Discussion
Squid Proxy Set-Cookie Headers Information Disclosure Vulnerability
Squid Proxy is prone to an information-disclosure vulnerability.
Reportedly, remote attackers may gain access to Set-Cookie headers related to another user. Information gathered through exploiting this issue may aid in further attacks against services related to the cookie, potentially allowing for session hijacking.
Squid Proxy 2.5 STABLE7 to 2.5 STABLE9 are vulnerable to this issue.
Squid Proxy is prone to an information-disclosure vulnerability.
Reportedly, remote attackers may gain access to Set-Cookie headers related to another user. Information gathered through exploiting this issue may aid in further attacks against services related to the cookie, potentially allowing for session hijacking.
Squid Proxy 2.5 STABLE7 to 2.5 STABLE9 are vulnerable to this issue.
Exploit / POC
Squid Proxy Set-Cookie Headers Information Disclosure Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Squid Proxy Set-Cookie Headers Information Disclosure Vulnerability
Solution:
Please see the referenced vendor advisories for more information and fixes.
Squid Web Proxy Cache 2.5 .STABLE9
Solution:
Please see the referenced vendor advisories for more information and fixes.
Squid Web Proxy Cache 2.5 .STABLE9
-
Squid squid-2.5.STABLE9-setcookie.patch
http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE9-setc ookie.patch
References
Squid Proxy Set-Cookie Headers Information Disclosure Vulnerability
References:
References: