CVE
- Id
- 11379
- CVE No.
- CVE-2005-0173
- Status
- Candidate
- Description
- squid_ldap_auth in Squid 2.5 and earlier allows remote authenticated users to bypass username-based Access Control Lists (ACLs) via a username with a space at the beginning or end, which is ignored by the LDAP server.
- Phase
- Assigned (20050127)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
80838 | 11379 | CVE-2005-0173 | CONFIRM:http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-ldap_spaces | View |
80839 | 11379 | CVE-2005-0173 | CONFIRM:http://www.squid-cache.org/bugs/show_bug.cgi?id=1187 | View |
80840 | 11379 | CVE-2005-0173 | CONFIRM:http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-ldap_spaces.patch | View |
80841 | 11379 | CVE-2005-0173 | CONECTIVA:CLA-2005:923 | View |
80842 | 11379 | CVE-2005-0173 | URL:http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000923 | View |
80843 | 11379 | CVE-2005-0173 | DEBIAN:DSA-667 | View |
80844 | 11379 | CVE-2005-0173 | URL:http://www.debian.org/security/2005/dsa-667 | View |
80845 | 11379 | CVE-2005-0173 | FEDORA:FLSA-2006:152809 | View |
80846 | 11379 | CVE-2005-0173 | URL:http://fedoranews.org/updates/FEDORA--.shtml | View |
80847 | 11379 | CVE-2005-0173 | MANDRAKE:MDKSA-2005:034 | View |
80848 | 11379 | CVE-2005-0173 | URL:http://www.mandriva.com/security/advisories?name=MDKSA-2005:034 | View |
80849 | 11379 | CVE-2005-0173 | REDHAT:RHSA-2005:060 | View |
80850 | 11379 | CVE-2005-0173 | URL:http://www.redhat.com/support/errata/RHSA-2005-060.html | View |
80851 | 11379 | CVE-2005-0173 | REDHAT:RHSA-2005:061 | View |
80852 | 11379 | CVE-2005-0173 | URL:http://www.redhat.com/support/errata/RHSA-2005-061.html | View |
80853 | 11379 | CVE-2005-0173 | SUSE:SUSE-SA:2005:006 | View |
80854 | 11379 | CVE-2005-0173 | URL:http://www.novell.com/linux/security/advisories/2005_06_squid.html | View |
80855 | 11379 | CVE-2005-0173 | CERT-VN:VU#924198 | View |
80856 | 11379 | CVE-2005-0173 | URL:http://www.kb.cert.org/vuls/id/924198 | View |
80857 | 11379 | CVE-2005-0173 | BUGTRAQ:20050207 [USN-77-1] Squid vulnerabilities | View |
80858 | 11379 | CVE-2005-0173 | URL:http://marc.info/?l=bugtraq&m=110780531820947&w=2 | View |
80859 | 11379 | CVE-2005-0173 | BID:12431 | View |
80860 | 11379 | CVE-2005-0173 | URL:http://www.securityfocus.com/bid/12431 | View |
80861 | 11379 | CVE-2005-0173 | OVAL:oval:org.mitre.oval:def:10251 | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
62725 | JVNDB-2004-000066 | HTTP レスポンスにおける改行コード (CR/LF) の扱いが不適切なためヘッダが分割可能な脆弱性 | 複数の HTTP サーバには、(1) HTTP リクエスト中の改行コード (CR/LF) の扱いが不適切なため、サーバのレスポンス中でヘッダを分割できてしまう脆弱性、(2) 一定の条件下において最初のリクエストに含まれる分割されたヘッダの後半部分を、二番目のリクエストへの応答として認識してしまう脆弱性が存在します。 | CVE-2005-0175 | 11379 | 5 | http://jvndb.jvn.jp/ja/contents/2004/JVNDB-2004-000066.html | View |