Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2005-0241
Description:The httpProcessReplyHeader function in http.c for Squid 2.5-STABLE7 and earlier does not properly set the debug context when it is handling "oversized" HTTP reply headers, which might allow remote attackers to poison the cache or bypass access controls based on header size.
Test IDs: 1.3.6.1.4.1.25623.1.0.54031   1.3.6.1.4.1.25623.1.0.52196  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2005-0241
BugTraq ID: 12412
http://www.securityfocus.com/bid/12412
CERT/CC vulnerability note: VU#823350
http://www.kb.cert.org/vuls/id/823350
Conectiva Linux advisory: CLA-2005:931
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000931
http://fedoranews.org/updates/FEDORA--.shtml
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10998
RedHat Security Advisories: RHSA-2005:060
http://www.redhat.com/support/errata/RHSA-2005-060.html
RedHat Security Advisories: RHSA-2005:061
http://www.redhat.com/support/errata/RHSA-2005-061.html
http://secunia.com/advisories/14091
SuSE Security Announcement: SUSE-SA:2005:006 (Google Search)
http://www.novell.com/linux/security/advisories/2005_06_squid.html
XForce ISS Database: squid-http-cache-poisoning(19060)
https://exchange.xforce.ibmcloud.com/vulnerabilities/19060




© 1998-2025 E-Soft Inc. All rights reserved.