Summary
The remote host is missing updates announced in
advisory GLSA 200403-11.
Solution
Squid can be updated as follows:
# emerge sync
# emerge -pv '>=www-proxy/squid-2.5.5'
# emerge '>=www-proxy/squid-2.5.5'
http://www.securityspace.com/smysecure/catid.html?in=GLSA%20200403-11 http://bugs.gentoo.org/show_bug.cgi?id=45273
http://www.squid-cache.org/Advisories/SQUID-2004_1.txt
Insight
Squid versions 2.0 through to 2.5.STABLE4 could allow a remote attacker to bypass Access Control Lists by sending a specially-crafted URL request containing '%00': in such circumstances
the url_regex ACL may not
properly detect the malicious URL, allowing the attacker to effectively bypass the ACL.
Severity
Classification
-
CVE CVE-2004-0189 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities