Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Debian: DSA-667-1 Urgent: Squid Remote Access Vulnerabilities Detected

debian
Calendar Grey February 4, 2005
Scroller Debian
- --------------------------------------------------------------------------Debian Security Advisory
LDAP is very forgiving about spaces in search filters and this could be abused to log in using several variants of the login name, possibly bypassing explicit access cont...

Summary


LDAP is very forgiving about spaces in search filters and this
could be abused to log in using several variants of the login
name, possibly bypassing explicit access controls or confusing
accounting.

CAN-2005-0175

Cache pollution/poisening via HTTP response splitting has been
discovered.

CAN-2005-0194

The meaning of the access controls becomes somewhat confusing if
any of the referenced ACLs (access control lists) is declared
empty, without any members.

CAN-2005-0211

The length argument of the WCCP recvfrom() call is larger than it
should be. An attacker may send a larger than normal WCCP packet
that could overflow a buffer.

For the stable distribution (woody) these problems have been fixed in
version 2.4.6-2woody6.

For the unstable distribution (sid) these problems have been fixed in
version 2.5.7-7.

We recommend that you upgrade your squid package.


Upgrade Instructions
- --------------------wget url
will fetch th...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.