CVE-2005-1345
https://notcve.org/view.php?id=CVE-2005-1345
Squid 2.5.STABLE9 and earlier does not trigger a fatal error when it identifies missing or invalid ACLs in the http_access configuration, which could lead to less restrictive ACLs than intended by the administrator. • http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000948 http://fedoranews.org/updates/FEDORA--.shtml http://www.debian.org/security/2005/dsa-721 http://www.redhat.com/support/errata/RHSA-2005-415.html http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE9-acl_error http://www.squid-cache.org/bugs/show_bug.cgi?id=1255 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10513 https://access.redhat.com/security •
CVE-2005-0718
https://notcve.org/view.php?id=CVE-2005-0718
Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (segmentation fault) by aborting the connection during a (1) PUT or (2) POST request, which causes Squid to access previously freed memory. • http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000931 http://fedoranews.org/updates/FEDORA--.shtml http://secunia.com/advisories/12508 http://www.redhat.com/support/errata/RHSA-2005-415.html http://www.redhat.com/support/errata/RHSA-2005-489.html http://www.securityfocus.com/bid/13166 http://www.squid-cache.org/bugs/show_bug.cgi?id=1224 http://www1.uk.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-post https://exchange.xforce.ibmcloud.co •
CVE-2005-0626
https://notcve.org/view.php?id=CVE-2005-0626
Race condition in Squid 2.5.STABLE7 to 2.5.STABLE9, when using the Netscape Set-Cookie recommendations for handling cookies in caches, may cause Set-Cookie headers to be sent to other users, which allows attackers to steal the related cookies. • http://fedoranews.org/updates/FEDORA--.shtml http://www.redhat.com/support/errata/RHSA-2005-415.html http://www.securityfocus.com/bid/12716 http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE9-setcookie https://exchange.xforce.ibmcloud.com/vulnerabilities/19581 https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11169 https://usn.ubuntu.com/93-1 https://access.redhat.com/security/cve/CVE-2005-0626 https://bugzilla.redhat.co •
CVE-2005-0446
https://notcve.org/view.php?id=CVE-2005-0446
Squid 2.5.STABLE8 and earlier allows remote attackers to cause a denial of service (crash) via certain DNS responses regarding (1) Fully Qualified Domain Names (FQDN) in fqdncache.c or (2) IP addresses in ipcache.c, which trigger an assertion failure. • http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000931 http://fedoranews.org/updates/FEDORA--.shtml http://marc.info/?l=bugtraq&m=110901183320453&w=2 http://secunia.com/advisories/14271 http://www.debian.org/security/2005/dsa-688 http://www.gentoo.org/security/en/glsa/glsa-200502-25.xml http://www.mandriva.com/security/advisories?name=MDKSA-2005:047 http://www.redhat.com/support/errata/RHSA-2005-173.html http://www.redhat.com/support/errata/RHSA-2005- •
CVE-2005-0241
https://notcve.org/view.php?id=CVE-2005-0241
The httpProcessReplyHeader function in http.c for Squid 2.5-STABLE7 and earlier does not properly set the debug context when it is handling "oversized" HTTP reply headers, which might allow remote attackers to poison the cache or bypass access controls based on header size. • http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000931 http://fedoranews.org/updates/FEDORA--.shtml http://secunia.com/advisories/14091 http://www.kb.cert.org/vuls/id/823350 http://www.novell.com/linux/security/advisories/2005_06_squid.html http://www.redhat.com/support/errata/RHSA-2005-060.html http://www.redhat.com/support/errata/RHSA-2005-061.html http://www.securityfocus.com/bid/12412 http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2 •