CVE-2005-0194
Publication date 2 May 2005
Last updated 24 July 2024
Ubuntu priority
Squid 2.5, when processing the configuration file, parses empty Access Control Lists (ACLs), including proxy_auth ACLs without defined auth schemes, in a way that effectively removes arguments, which could allow remote attackers to bypass intended ACLs if the administrator ignores the parser warnings.
Status
Package | Ubuntu Release | Status |
---|---|---|
squid | 7.04 feisty |
Fixed 2.6.5-4ubuntu2
|
6.10 edgy |
Fixed 2.6.1-3ubuntu1.3
|
|
6.06 LTS dapper |
Fixed 2.5.12-4ubuntu2.2
|