Squid Proxy HTTP Response Splitting Remote Cache Poisoning Vulnerability
BID:13435
Info
Squid Proxy HTTP Response Splitting Remote Cache Poisoning Vulnerability
| Bugtraq ID: | 13435 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 23 2005 12:00AM |
| Updated: | Apr 23 2005 12:00AM |
| Credit: | Watchfire is credited with the discovery of this issue. |
| Vulnerable: |
Squid Web Proxy Cache 2.5 .STABLE7 Squid Web Proxy Cache 2.5 .STABLE6 Squid Web Proxy Cache 2.5 .STABLE5 Squid Web Proxy Cache 2.5 .STABLE4 Squid Web Proxy Cache 2.5 .STABLE3 Squid Web Proxy Cache 2.5 .STABLE1 Squid Web Proxy Cache 2.4 .STABLE7 Squid Web Proxy Cache 2.4 .STABLE6 Squid Web Proxy Cache 2.4 .STABLE2 Squid Web Proxy Cache 2.4 Squid Web Proxy Cache 2.3 .STABLE5 Squid Web Proxy Cache 2.3 .STABLE4 Squid Web Proxy Cache 2.1 PATCH2 Squid Web Proxy Cache 2.0 PATCH2 |
| Not Vulnerable: |
Squid Web Proxy Cache 2.5 .STABLE9 Squid Web Proxy Cache 2.5 .STABLE8 |
Discussion
Squid Proxy HTTP Response Splitting Remote Cache Poisoning Vulnerability
A remote cache poisoning vulnerability affects Squid Proxy. This issue is due to a failure of the affected proxy to handle CR/LF characters in HTTP requests.
An attacker may leverage this issue to poison the cache of an affected Squid Proxy. This may facilitate man-in-the-middle attacks as well as others.
A remote cache poisoning vulnerability affects Squid Proxy. This issue is due to a failure of the affected proxy to handle CR/LF characters in HTTP requests.
An attacker may leverage this issue to poison the cache of an affected Squid Proxy. This may facilitate man-in-the-middle attacks as well as others.
Exploit / POC
Squid Proxy HTTP Response Splitting Remote Cache Poisoning Vulnerability
No exploit is required to leverage this issue.
No exploit is required to leverage this issue.
Solution / Fix
Squid Proxy HTTP Response Splitting Remote Cache Poisoning Vulnerability
Solution:
The vendor has released an upgrade dealing with this issue.
Squid Web Proxy Cache 2.0 PATCH2
Squid Web Proxy Cache 2.1 PATCH2
Squid Web Proxy Cache 2.3 .STABLE4
Squid Web Proxy Cache 2.3 .STABLE5
Squid Web Proxy Cache 2.4 .STABLE6
Squid Web Proxy Cache 2.4 .STABLE7
Squid Web Proxy Cache 2.4
Squid Web Proxy Cache 2.4 .STABLE2
Squid Web Proxy Cache 2.5 .STABLE6
Squid Web Proxy Cache 2.5 .STABLE4
Squid Web Proxy Cache 2.5 .STABLE1
Squid Web Proxy Cache 2.5 .STABLE5
Squid Web Proxy Cache 2.5 .STABLE3
Squid Web Proxy Cache 2.5 .STABLE7
Solution:
The vendor has released an upgrade dealing with this issue.
Squid Web Proxy Cache 2.0 PATCH2
-
Squid Squid 2.5.STABLE9
http://www.squid-cache.org/Versions/v2/2.5/squid-2.5.STABLE9.tar.gz
Squid Web Proxy Cache 2.1 PATCH2
-
Squid Squid 2.5.STABLE9
http://www.squid-cache.org/Versions/v2/2.5/squid-2.5.STABLE9.tar.gz
Squid Web Proxy Cache 2.3 .STABLE4
-
Squid Squid 2.5.STABLE9
http://www.squid-cache.org/Versions/v2/2.5/squid-2.5.STABLE9.tar.gz
Squid Web Proxy Cache 2.3 .STABLE5
-
Squid Squid 2.5.STABLE9
http://www.squid-cache.org/Versions/v2/2.5/squid-2.5.STABLE9.tar.gz
Squid Web Proxy Cache 2.4 .STABLE6
-
Squid Squid 2.5.STABLE9
http://www.squid-cache.org/Versions/v2/2.5/squid-2.5.STABLE9.tar.gz
Squid Web Proxy Cache 2.4 .STABLE7
-
Squid Squid 2.5.STABLE9
http://www.squid-cache.org/Versions/v2/2.5/squid-2.5.STABLE9.tar.gz
Squid Web Proxy Cache 2.4
-
Squid Squid 2.5.STABLE9
http://www.squid-cache.org/Versions/v2/2.5/squid-2.5.STABLE9.tar.gz
Squid Web Proxy Cache 2.4 .STABLE2
-
Squid Squid 2.5.STABLE9
http://www.squid-cache.org/Versions/v2/2.5/squid-2.5.STABLE9.tar.gz
Squid Web Proxy Cache 2.5 .STABLE6
-
Squid Squid 2.5.STABLE9
http://www.squid-cache.org/Versions/v2/2.5/squid-2.5.STABLE9.tar.gz
Squid Web Proxy Cache 2.5 .STABLE4
-
Squid Squid 2.5.STABLE9
http://www.squid-cache.org/Versions/v2/2.5/squid-2.5.STABLE9.tar.gz
Squid Web Proxy Cache 2.5 .STABLE1
-
Squid Squid 2.5.STABLE9
http://www.squid-cache.org/Versions/v2/2.5/squid-2.5.STABLE9.tar.gz
Squid Web Proxy Cache 2.5 .STABLE5
-
Squid Squid 2.5.STABLE9
http://www.squid-cache.org/Versions/v2/2.5/squid-2.5.STABLE9.tar.gz
Squid Web Proxy Cache 2.5 .STABLE3
-
Squid Squid 2.5.STABLE9
http://www.squid-cache.org/Versions/v2/2.5/squid-2.5.STABLE9.tar.gz
Squid Web Proxy Cache 2.5 .STABLE7
-
Squid Squid 2.5.STABLE9
http://www.squid-cache.org/Versions/v2/2.5/squid-2.5.STABLE9.tar.gz
References
Squid Proxy HTTP Response Splitting Remote Cache Poisoning Vulnerability
References:
References: