CVE-2004-2479
published 2004-12-31CVE-2004-2479: Squid Web Proxy Cache 2.5 might allow remote attackers to obtain sensitive information via URLs containing invalid hostnames that cause DNS operations to fail…
PriorityP414medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
2.08%
79.6th percentile
Squid Web Proxy Cache 2.5 might allow remote attackers to obtain sensitive information via URLs containing invalid hostnames that cause DNS operations to fail, which results in references to previously used error messages.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | squid | < squid 2.5.8 (bookworm) | squid 2.5.8 (bookworm) |
| national_science_foundation | squid_web_proxy_cache | — | — |
| national_science_foundation | squid_web_proxy_cache | — | — |
| national_science_foundation | squid_web_proxy_cache | — | — |
| national_science_foundation | squid_web_proxy_cache | — | — |
| national_science_foundation | squid_web_proxy_cache | — | — |
| national_science_foundation | squid_web_proxy_cache | — | — |
| national_science_foundation | squid_web_proxy_cache | — | — |
| squid | squid | >= 0 < 2.5.8 | 2.5.8 |
| squid | squid | >= 0 < 2.5.8 | 2.5.8 |
| squid | squid | >= 0 < 2.5.8 | 2.5.8 |
| squid | squid | >= 0 < 2.5.8 | 2.5.8 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
security flaw
vendor_redhat·2004-11-23·CVSS 5.0
CVE-2004-2479 [MEDIUM] security flaw
security flaw
Squid Web Proxy Cache 2.5 might allow remote attackers to obtain sensitive information via URLs containing invalid hostnames that cause DNS operations to fail, which results in references to previously used error messages.
Debian
CVE-2004-2479: squid - Squid Web Proxy Cache 2.5 might allow remote attackers to obtain sensitive infor...
vendor_debian·2004·CVSS 5.0
CVE-2004-2479 [MEDIUM] CVE-2004-2479: squid - Squid Web Proxy Cache 2.5 might allow remote attackers to obtain sensitive infor...
Squid Web Proxy Cache 2.5 might allow remote attackers to obtain sensitive information via URLs containing invalid hostnames that cause DNS operations to fail, which results in references to previously used error messages.
Scope: local
bookworm: resolved (fixed in 2.5.8)
bullseye: resolved (fixed in 2.5.8)
forky: resolved (fixed in 2.5.8)
sid: resolved (fixed in 2.5.8)
trixie: resolved (fixed in 2.5.8)
GHSA
GHSA-wf7x-gjvh-m5r3: Squid Web Proxy Cache 2
ghsa_unreviewed·2022-04-29
CVE-2004-2479 [MEDIUM] GHSA-wf7x-gjvh-m5r3: Squid Web Proxy Cache 2
Squid Web Proxy Cache 2.5 might allow remote attackers to obtain sensitive information via URLs containing invalid hostnames that cause DNS operations to fail, which results in references to previously used error messages.
OSV
CVE-2004-2479: Squid Web Proxy Cache 2
osv·2004-12-31·CVSS 5.0
CVE-2004-2479 [MEDIUM] CVE-2004-2479: Squid Web Proxy Cache 2
Squid Web Proxy Cache 2.5 might allow remote attackers to obtain sensitive information via URLs containing invalid hostnames that cause DNS operations to fail, which results in references to previously used error messages.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2004-2479 security flaw
bugzilla·2018-08-16·CVSS 5.0
CVE-2004-2479 [MEDIUM] CVE-2004-2479 security flaw
CVE-2004-2479 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Squid Web Proxy Cache 2.5 might allow remote attackers to obtain sensitive information via URLs containing invalid hostnames that cause DNS operations to fail, which results in references to previously used error messages.
Bugzilla
Squid Multiple Vulnerabilities (CVE-2004-0541 CVE-2004-0832 CVE-2004-0918 CVE-2005-0094 CVE-2005-0095 CVE-2005-0096 CVE-2005-0097 CVE-2005-0446 CVE-2005-0626 CVE-2005-0718 CVE-1999-0710 CVE-2005-1345
bugzilla·2004-10-11·CVSS 7.5
CVE-2004-0541 [HIGH] Squid Multiple Vulnerabilities (CVE-2004-0541 CVE-2004-0832 CVE-2004-0918 CVE-2005-0094 CVE-2005-0095 CVE-2005-0096 CVE-2005-0097 CVE-2005-0446 CVE-2005-0626 CVE-2005-0718 CVE-1999-0710 CVE-2005-1345
Squid Multiple Vulnerabilities (CVE-2004-0541 CVE-2004-0832 CVE-2004-0918 CVE-2005-0094 CVE-2005-0095 CVE-2005-0096 CVE-2005-0097 CVE-2005-0446 CVE-2005-0626 CVE-2005-0718 CVE-1999-0710 CVE-2005-1345 CVE-2005-1519 CVE-2004-2479 CVE-2005-2794 CVE-2005-...
iDEFENSE reported on 2004-10-11 a vulnerability in the squid SNMP
module. This issue could lead to a potential DOS (it will restart
the server, dropping all open connections).
http://www.idefense.com/application/poi/display?id=152&type=vulnerabilities
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=135320
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=135319
------- Additional Comments From [email protected] 2004-10-11 19:30:05 ----
Patch available here:
http://www1.uk.squid-cache.org/squid/Versions/v2/2
http://fedoranews.org/updates/FEDORA--.shtmlhttp://secunia.com/advisories/13408http://secunia.com/advisories/16977http://securitytracker.com/id?1012466http://www.osvdb.org/12282http://www.redhat.com/support/errata/RHSA-2005-766.htmlhttp://www.securityfocus.com/bid/11865http://www.squid-cache.org/bugs/show_bug.cgi?id=1143https://exchange.xforce.ibmcloud.com/vulnerabilities/18406https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9711http://fedoranews.org/updates/FEDORA--.shtmlhttp://secunia.com/advisories/13408http://secunia.com/advisories/16977http://securitytracker.com/id?1012466http://www.osvdb.org/12282http://www.redhat.com/support/errata/RHSA-2005-766.htmlhttp://www.securityfocus.com/bid/11865http://www.squid-cache.org/bugs/show_bug.cgi?id=1143https://exchange.xforce.ibmcloud.com/vulnerabilities/18406https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9711
2004-12-31
Published