Race condition in Squid 2.5.STABLE7 to 2.5.STABLE9, when using the Netscape Set-Cookie recommendations for handling cookies in caches, may cause Set-Cookie headers to be sent to other users, which allows attackers to steal the related cookies.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Squid | Squid | 2.5.stable5 (including) | 2.5.stable5 (including) |
| Squid | Squid | 2.5.stable6 (including) | 2.5.stable6 (including) |
| Squid | Squid | 2.5.stable7 (including) | 2.5.stable7 (including) |
| Red Hat Enterprise Linux 3 | RedHat | squid-7:2.5.STABLE3-6.3E.13 | * |
| Red Hat Enterprise Linux 4 | RedHat | squid-7:2.5.STABLE6-3.4E.9 | * |