CVE Vulnerabilities

CVE-2005-0626

Published: Mar 08, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.6 LOW
AV:N/AC:H/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Race condition in Squid 2.5.STABLE7 to 2.5.STABLE9, when using the Netscape Set-Cookie recommendations for handling cookies in caches, may cause Set-Cookie headers to be sent to other users, which allows attackers to steal the related cookies.

Affected Software

NameVendorStart VersionEnd Version
SquidSquid2.5.stable5 (including)2.5.stable5 (including)
SquidSquid2.5.stable6 (including)2.5.stable6 (including)
SquidSquid2.5.stable7 (including)2.5.stable7 (including)
Red Hat Enterprise Linux 3RedHatsquid-7:2.5.STABLE3-6.3E.13*
Red Hat Enterprise Linux 4RedHatsquid-7:2.5.STABLE6-3.4E.9*

References