Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Gentoo: GLSA 200606-05 Moderate: Pound HTTP Smuggling Threat

gentoo
Calendar Grey June 7, 2006
Dist Gentoo Esm H88
Gentoo GLSA 202310-14 highlights critical vulnerabilities in Nginx. Update promptly to enhance security measures.
Pound is vulnerable to HTTP request smuggling, which could be exploited to bypass security restrictions or poison web caches.

Summary

Gentoo Linux Security Advisory GLSA 200606-05 https://security.gentoo.org/ Severity: Low Title: Pound: HTTP request smuggling Date: June 07, 2006 Bugs: #118541 ID: 200606-05

Synopsis ======= Pound is vulnerable to HTTP request smuggling, which could be exploited to bypass security restrictions or poison web caches.
Background ========= Pound is a reverse proxy, load balancer and HTTPS front-end. It allows to distribute the load on several web servers and offers a SSL wrapper for web servers that do not support SSL directly.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-servers/pound < 2.0.5 >= 2.0.5
========== Pound fails to handle HTTP requests wi...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Severity
low
Lowest
Low
Medium
High
Critical

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround

Related News

Your message here