CVE-1999-0710
published 1999-07-25CVE-1999-0710: The Squid package in Red Hat Linux 5.2 and 6.0, and other distributions, installs cachemgr.cgi in a public web directory, which allows remote attackers to use…
PriorityP336high7.5CVSS 2.0
AVNACLAuNCPIPAP
EXPLOIT
EPSS
11.60%
95.6th percentile
The Squid package in Red Hat Linux 5.2 and 6.0, and other distributions, installs cachemgr.cgi in a public web directory, which allows remote attackers to use it as an intermediary to connect to other systems.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | squid | < squid 2.5.7-1 (bookworm) | squid 2.5.7-1 (bookworm) |
| redhat | linux | — | — |
| redhat | linux | — | — |
| squid | squid | >= 0 < 2.5.7-1 | 2.5.7-1 |
| squid | squid | >= 0 < 2.5.7-1 | 2.5.7-1 |
| squid | squid | >= 0 < 2.5.7-1 | 2.5.7-1 |
| squid | squid | >= 0 < 2.5.7-1 | 2.5.7-1 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qhrx-x4p7-jr4j: The Squid package in Red Hat Linux 5
ghsa_unreviewed·2022-04-30
CVE-1999-0710 [HIGH] GHSA-qhrx-x4p7-jr4j: The Squid package in Red Hat Linux 5
The Squid package in Red Hat Linux 5.2 and 6.0, and other distributions, installs cachemgr.cgi in a public web directory, which allows remote attackers to use it as an intermediary to connect to other systems.
OSV
CVE-1999-0710: The Squid package in Red Hat Linux 5
osv·1999-07-25·CVSS 7.5
CVE-1999-0710 [HIGH] CVE-1999-0710: The Squid package in Red Hat Linux 5
The Squid package in Red Hat Linux 5.2 and 6.0, and other distributions, installs cachemgr.cgi in a public web directory, which allows remote attackers to use it as an intermediary to connect to other systems.
Red Hat
security flaw
vendor_redhat·1999-07-25·CVSS 7.5
CVE-1999-0710 [HIGH] security flaw
security flaw
The Squid package in Red Hat Linux 5.2 and 6.0, and other distributions, installs cachemgr.cgi in a public web directory, which allows remote attackers to use it as an intermediary to connect to other systems.
Debian
CVE-1999-0710: squid - The Squid package in Red Hat Linux 5.2 and 6.0, and other distributions, install...
vendor_debian·1999·CVSS 7.5
CVE-1999-0710 [HIGH] CVE-1999-0710: squid - The Squid package in Red Hat Linux 5.2 and 6.0, and other distributions, install...
The Squid package in Red Hat Linux 5.2 and 6.0, and other distributions, installs cachemgr.cgi in a public web directory, which allows remote attackers to use it as an intermediary to connect to other systems.
Scope: local
bookworm: resolved (fixed in 2.5.7-1)
bullseye: resolved (fixed in 2.5.7-1)
forky: resolved (fixed in 2.5.7-1)
sid: resolved (fixed in 2.5.7-1)
trixie: resolved (fixed in 2.5.7-1)
No detection rules found.
Bugzilla
CVE-1999-0710 security flaw
bugzilla·2018-08-16·CVSS 7.5
CVE-1999-0710 [HIGH] CVE-1999-0710 security flaw
CVE-1999-0710 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
The Squid package in Red Hat Linux 5.2 and 6.0, and other distributions, installs cachemgr.cgi in a public web directory, which allows remote attackers to use it as an intermediary to connect to other systems.
Bugzilla
CVE-1999-0710 cachemgr.cgi access control bypass
bugzilla·2005-04-28·CVSS 7.5
CVE-1999-0710 [HIGH] CVE-1999-0710 cachemgr.cgi access control bypass
CVE-1999-0710 cachemgr.cgi access control bypass
+++ This bug was initially created as a clone of Bug #156161 +++
The RedHat squid program installs cachemgr.cgi in a public web directory,
allowing remote attackers to use it as an intermediary to connect to other systems.
This patch adds access controls to the cachemgr.cgi script, preventing it from
being abused to reach other servers than allowed in a local configuration file.
http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE9-cachemgr_conf
Bugzilla
CVE-1999-0710 cachemgr.cgi access control bypass
bugzilla·2005-04-28·CVSS 7.5
CVE-1999-0710 [HIGH] CVE-1999-0710 cachemgr.cgi access control bypass
CVE-1999-0710 cachemgr.cgi access control bypass
The RedHat squid program installs cachemgr.cgi in a public web directory,
allowing remote attackers to use it as an intermediary to connect to other systems.
This patch adds access controls to the cachemgr.cgi script, preventing it from
being abused to reach other servers than allowed in a local configuration file.
http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE9-cachemgr_conf
Discussion:
This issue should also affect RHEL2.1 and RHEL3
---
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this
Bugzilla
Squid Multiple Vulnerabilities (CVE-2004-0541 CVE-2004-0832 CVE-2004-0918 CVE-2005-0094 CVE-2005-0095 CVE-2005-0096 CVE-2005-0097 CVE-2005-0446 CVE-2005-0626 CVE-2005-0718 CVE-1999-0710 CVE-2005-1345
bugzilla·2004-10-11·CVSS 7.5
CVE-2004-0541 [HIGH] Squid Multiple Vulnerabilities (CVE-2004-0541 CVE-2004-0832 CVE-2004-0918 CVE-2005-0094 CVE-2005-0095 CVE-2005-0096 CVE-2005-0097 CVE-2005-0446 CVE-2005-0626 CVE-2005-0718 CVE-1999-0710 CVE-2005-1345
Squid Multiple Vulnerabilities (CVE-2004-0541 CVE-2004-0832 CVE-2004-0918 CVE-2005-0094 CVE-2005-0095 CVE-2005-0096 CVE-2005-0097 CVE-2005-0446 CVE-2005-0626 CVE-2005-0718 CVE-1999-0710 CVE-2005-1345 CVE-2005-1519 CVE-2004-2479 CVE-2005-2794 CVE-2005-...
iDEFENSE reported on 2004-10-11 a vulnerability in the squid SNMP
module. This issue could lead to a potential DOS (it will restart
the server, dropping all open connections).
http://www.idefense.com/application/poi/display?id=152&type=vulnerabilities
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=135320
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=135319
------- Additional Comments From [email protected] 2004-10-11 19:30:05 ----
Patch available here:
http://www1.uk.squid-cache.org/squid/Versions/v2/2
http://fedoranews.org/updates/FEDORA--.shtmlhttp://www.debian.org/security/2004/dsa-576http://www.redhat.com/archives/fedora-announce-list/2005-May/msg00025.htmlhttp://www.redhat.com/support/errata/RHSA-1999-025.htmlhttp://www.redhat.com/support/errata/RHSA-2005-489.htmlhttp://www.redhat.com/support/errata/archives/rh52-errata-general.html#squidhttp://www.securityfocus.com/bid/2059https://exchange.xforce.ibmcloud.com/vulnerabilities/2385http://fedoranews.org/updates/FEDORA--.shtmlhttp://www.debian.org/security/2004/dsa-576http://www.redhat.com/archives/fedora-announce-list/2005-May/msg00025.htmlhttp://www.redhat.com/support/errata/RHSA-1999-025.htmlhttp://www.redhat.com/support/errata/RHSA-2005-489.htmlhttp://www.redhat.com/support/errata/archives/rh52-errata-general.html#squidhttp://www.securityfocus.com/bid/2059https://exchange.xforce.ibmcloud.com/vulnerabilities/2385
1999-07-25
Published