Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Gentoo: GLSA 200606-05 Moderate: Pound HTTP Smuggling Threat

gentoo
Calendar Grey June 7, 2006
Scroller Gentoo
Gentoo GLSA 202310-14 highlights critical vulnerabilities in Nginx. Update promptly to enhance security measures.
Pound is vulnerable to HTTP request smuggling, which could be exploited to bypass security restrictions or poison web caches.

Summary

Gentoo Linux Security Advisory GLSA 200606-05 https://security.gentoo.org/ Severity: Low Title: Pound: HTTP request smuggling Date: June 07, 2006 Bugs: #118541 ID: 200606-05

Synopsis ======= Pound is vulnerable to HTTP request smuggling, which could be exploited to bypass security restrictions or poison web caches.
Background ========= Pound is a reverse proxy, load balancer and HTTPS front-end. It allows to distribute the load on several web servers and offers a SSL wrapper for web servers that do not support SSL directly.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-servers/pound < 2.0.5 >= 2.0.5
========== Pound fails to handle HTTP requests wi...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Severity
low
Lowest
Low
Medium
High
Critical

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround