The Squid package in Red Hat Linux 5.2 and 6.0, and other distributions, installs cachemgr.cgi in a public web directory, which allows remote attackers to use it as an intermediary to connect to other systems.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Linux | Redhat | 5.2 (including) | 5.2 (including) |
Linux | Redhat | 6.0 (including) | 6.0 (including) |
Red Hat Enterprise Linux 3 | RedHat | squid-7:2.5.STABLE3-6.3E.13 | * |
Red Hat Enterprise Linux 4 | RedHat | squid-7:2.5.STABLE6-3.4E.9 | * |
Red Hat Enterprise Linux AS (Advanced Server) version 2.1 | RedHat | * | |
Red Hat Enterprise Linux ES version 2.1 | RedHat | * | |
Red Hat Linux Advanced Workstation 2.1 | RedHat | * |