Description
Race condition in Squid 2.5.STABLE7 to 2.5.STABLE9, when using the Netscape Set-Cookie recommendations for handling cookies in caches, may cause Set-Cookie headers to be sent to other users, which allows attackers to steal the related cookies.
CVSS vector
AV:N/AC:H/C:P/I:N/A:NExploitability: 4.9 | Impact: 2.9Complexity: High
Integrity: None
Availability: None
Affected Packages2 packages
🔴Vulnerability Details
3GHSAGHSA-h49j-p65c-g4qj: Race condition in Squid 2↗2022-05-01 ▶ OSVCVE-2005-0626: Race condition in Squid 2↗2005-03-08 ▶ CVEListCVE-2005-0626: Race condition in Squid 2↗2005-03-03 ▶ 📋Vendor Advisories
3UbuntuSquid vulnerability↗2005-03-08 ▶ DebianCVE-2005-0626: squid - Race condition in Squid 2.5.STABLE7 to 2.5.STABLE9, when using the Netscape Set-...↗2005 ▶ 💬Community
2BugzillaCVE-2005-0626 security flaw↗2018-08-16 ▶ BugzillaSquid Multiple Vulnerabilities (CVE-2004-0541 CVE-2004-0832 CVE-2004-0918 CVE-2005-0094 CVE-2005-0095 CVE-2005-0096 CVE-2005-0097 CVE-2005-0446 CVE-2005-0626 CVE-2005-0718 CVE-1999-0710 CVE-2005-1345↗2004-10-11 ▶