CVE-2005-0626
published 2005-03-08CVE-2005-0626: Race condition in Squid 2.5.STABLE7 to 2.5.STABLE9, when using the Netscape Set-Cookie recommendations for handling cookies in caches, may cause Set-Cookie…
PriorityP49low2.6CVSS 2.0
AVNACHAuNCPINAN
EPSS
1.35%
68.6th percentile
Race condition in Squid 2.5.STABLE7 to 2.5.STABLE9, when using the Netscape Set-Cookie recommendations for handling cookies in caches, may cause Set-Cookie headers to be sent to other users, which allows attackers to steal the related cookies.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | squid | < squid 2.5.9-2 (bookworm) | squid 2.5.9-2 (bookworm) |
| squid | squid | — | — |
| squid | squid | — | — |
| squid | squid | — | — |
| squid | squid | >= 0 < 2.5.9-2 | 2.5.9-2 |
| squid | squid | >= 0 < 2.5.9-2 | 2.5.9-2 |
| squid | squid | >= 0 < 2.5.9-2 | 2.5.9-2 |
| squid | squid | >= 0 < 2.5.9-2 | 2.5.9-2 |
CVSS provenance
nvdv2.02.6LOWAV:N/AC:H/Au:N/C:P/I:N/A:N
osv2.6LOW
vendor_debian2.6LOW
vendor_redhat2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Squid vulnerability
vendor_ubuntu·2005-03-08
CVE-2005-0626 Squid vulnerability
Title: Squid vulnerability
Summary: Squid vulnerability
A race condition was discovered in the handling of "Set-Cookie"
headers. If the obsolete Netscape recommendation was used for handling
cookies in the cache, it was possible for an attacker to steal the
cookies of other users.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
security flaw
vendor_redhat·2005-03-02·CVSS 2.6
CVE-2005-0626 [LOW] security flaw
security flaw
Race condition in Squid 2.5.STABLE7 to 2.5.STABLE9, when using the Netscape Set-Cookie recommendations for handling cookies in caches, may cause Set-Cookie headers to be sent to other users, which allows attackers to steal the related cookies.
Debian
CVE-2005-0626: squid - Race condition in Squid 2.5.STABLE7 to 2.5.STABLE9, when using the Netscape Set-...
vendor_debian·2005·CVSS 2.6
CVE-2005-0626 [LOW] CVE-2005-0626: squid - Race condition in Squid 2.5.STABLE7 to 2.5.STABLE9, when using the Netscape Set-...
Race condition in Squid 2.5.STABLE7 to 2.5.STABLE9, when using the Netscape Set-Cookie recommendations for handling cookies in caches, may cause Set-Cookie headers to be sent to other users, which allows attackers to steal the related cookies.
Scope: local
bookworm: resolved (fixed in 2.5.9-2)
bullseye: resolved (fixed in 2.5.9-2)
forky: resolved (fixed in 2.5.9-2)
sid: resolved (fixed in 2.5.9-2)
trixie: resolved (fixed in 2.5.9-2)
GHSA
GHSA-h49j-p65c-g4qj: Race condition in Squid 2
ghsa_unreviewed·2022-05-01
CVE-2005-0626 [LOW] GHSA-h49j-p65c-g4qj: Race condition in Squid 2
Race condition in Squid 2.5.STABLE7 to 2.5.STABLE9, when using the Netscape Set-Cookie recommendations for handling cookies in caches, may cause Set-Cookie headers to be sent to other users, which allows attackers to steal the related cookies.
OSV
CVE-2005-0626: Race condition in Squid 2
osv·2005-03-08·CVSS 2.6
CVE-2005-0626 [LOW] CVE-2005-0626: Race condition in Squid 2
Race condition in Squid 2.5.STABLE7 to 2.5.STABLE9, when using the Netscape Set-Cookie recommendations for handling cookies in caches, may cause Set-Cookie headers to be sent to other users, which allows attackers to steal the related cookies.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2005-0626 security flaw
bugzilla·2018-08-16·CVSS 2.6
CVE-2005-0626 [LOW] CVE-2005-0626 security flaw
CVE-2005-0626 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Race condition in Squid 2.5.STABLE7 to 2.5.STABLE9, when using the Netscape Set-Cookie recommendations for handling cookies in caches, may cause Set-Cookie headers to be sent to other users, which allows attackers to steal the related cookies.
Bugzilla
Squid Multiple Vulnerabilities (CVE-2004-0541 CVE-2004-0832 CVE-2004-0918 CVE-2005-0094 CVE-2005-0095 CVE-2005-0096 CVE-2005-0097 CVE-2005-0446 CVE-2005-0626 CVE-2005-0718 CVE-1999-0710 CVE-2005-1345
bugzilla·2004-10-11·CVSS 7.5
CVE-2004-0541 [HIGH] Squid Multiple Vulnerabilities (CVE-2004-0541 CVE-2004-0832 CVE-2004-0918 CVE-2005-0094 CVE-2005-0095 CVE-2005-0096 CVE-2005-0097 CVE-2005-0446 CVE-2005-0626 CVE-2005-0718 CVE-1999-0710 CVE-2005-1345
Squid Multiple Vulnerabilities (CVE-2004-0541 CVE-2004-0832 CVE-2004-0918 CVE-2005-0094 CVE-2005-0095 CVE-2005-0096 CVE-2005-0097 CVE-2005-0446 CVE-2005-0626 CVE-2005-0718 CVE-1999-0710 CVE-2005-1345 CVE-2005-1519 CVE-2004-2479 CVE-2005-2794 CVE-2005-...
iDEFENSE reported on 2004-10-11 a vulnerability in the squid SNMP
module. This issue could lead to a potential DOS (it will restart
the server, dropping all open connections).
http://www.idefense.com/application/poi/display?id=152&type=vulnerabilities
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=135320
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=135319
------- Additional Comments From [email protected] 2004-10-11 19:30:05 ----
Patch available here:
http://www1.uk.squid-cache.org/squid/Versions/v2/2
http://fedoranews.org/updates/FEDORA--.shtmlhttp://www.redhat.com/support/errata/RHSA-2005-415.htmlhttp://www.securityfocus.com/bid/12716http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE9-setcookiehttps://exchange.xforce.ibmcloud.com/vulnerabilities/19581https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11169https://usn.ubuntu.com/93-1/http://fedoranews.org/updates/FEDORA--.shtmlhttp://www.redhat.com/support/errata/RHSA-2005-415.htmlhttp://www.securityfocus.com/bid/12716http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE9-setcookiehttps://exchange.xforce.ibmcloud.com/vulnerabilities/19581https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11169https://usn.ubuntu.com/93-1/
2005-03-08
Published