CVE Vulnerabilities

CVE-2005-0173

Published: May 02, 2005 | Modified: Oct 11, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
UNTRIAGED

squid_ldap_auth in Squid 2.5 and earlier allows remote authenticated users to bypass username-based Access Control Lists (ACLs) via a username with a space at the beginning or end, which is ignored by the LDAP server.

Affected Software

Name Vendor Start Version End Version
Squid Squid 2.0.patch1 (including) 2.0.patch1 (including)
Squid Squid 2.0.patch2 (including) 2.0.patch2 (including)
Squid Squid 2.0.pre1 (including) 2.0.pre1 (including)
Squid Squid 2.0.release (including) 2.0.release (including)
Squid Squid 2.1.patch1 (including) 2.1.patch1 (including)
Squid Squid 2.1.patch2 (including) 2.1.patch2 (including)
Squid Squid 2.1.pre1 (including) 2.1.pre1 (including)
Squid Squid 2.1.pre3 (including) 2.1.pre3 (including)
Squid Squid 2.1.pre4 (including) 2.1.pre4 (including)
Squid Squid 2.1.release (including) 2.1.release (including)
Squid Squid 2.2.devel3 (including) 2.2.devel3 (including)
Squid Squid 2.2.devel4 (including) 2.2.devel4 (including)
Squid Squid 2.2.pre1 (including) 2.2.pre1 (including)
Squid Squid 2.2.pre2 (including) 2.2.pre2 (including)
Squid Squid 2.2.stable1 (including) 2.2.stable1 (including)
Squid Squid 2.2.stable2 (including) 2.2.stable2 (including)
Squid Squid 2.2.stable3 (including) 2.2.stable3 (including)
Squid Squid 2.2.stable4 (including) 2.2.stable4 (including)
Squid Squid 2.2.stable5 (including) 2.2.stable5 (including)
Squid Squid 2.3.devel2 (including) 2.3.devel2 (including)
Squid Squid 2.3.devel3 (including) 2.3.devel3 (including)
Squid Squid 2.3.stable1 (including) 2.3.stable1 (including)
Squid Squid 2.3.stable2 (including) 2.3.stable2 (including)
Squid Squid 2.3.stable3 (including) 2.3.stable3 (including)
Squid Squid 2.3.stable4 (including) 2.3.stable4 (including)
Squid Squid 2.3.stable5 (including) 2.3.stable5 (including)
Squid Squid 2.4.stable1 (including) 2.4.stable1 (including)
Squid Squid 2.4.stable2 (including) 2.4.stable2 (including)
Squid Squid 2.4.stable3 (including) 2.4.stable3 (including)
Squid Squid 2.4.stable4 (including) 2.4.stable4 (including)
Squid Squid 2.4.stable6 (including) 2.4.stable6 (including)
Squid Squid 2.4.stable7 (including) 2.4.stable7 (including)
Squid Squid 2.5.stable1 (including) 2.5.stable1 (including)
Squid Squid 2.5.stable2 (including) 2.5.stable2 (including)
Squid Squid 2.5.stable3 (including) 2.5.stable3 (including)
Squid Squid 2.5.stable4 (including) 2.5.stable4 (including)
Squid Squid 2.5.stable5 (including) 2.5.stable5 (including)
Squid Squid 2.5.stable6 (including) 2.5.stable6 (including)
Red Hat Enterprise Linux 3 RedHat squid-7:2.5.STABLE3-6.3E.7 *
Red Hat Enterprise Linux 4 RedHat squid-7:2.5.STABLE6-3.4E.3 *
Squid Ubuntu dapper *
Squid Ubuntu devel *
Squid Ubuntu edgy *
Squid Ubuntu feisty *

References