CVE-2005-1519
published 2005-05-11CVE-2005-1519: Squid 2.5 STABLE9 and earlier, when the DNS client port is unfiltered and the environment does not prevent IP spoofing, allows remote attackers to spoof DNS…
PriorityP424medium6.4CVSS 2.0
AVNACLAuNCNIPAP
EPSS
2.36%
82.0th percentile
Squid 2.5 STABLE9 and earlier, when the DNS client port is unfiltered and the environment does not prevent IP spoofing, allows remote attackers to spoof DNS lookups.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | squid | < squid 2.5.9-9 (bookworm) | squid 2.5.9-9 (bookworm) |
| squid | squid | <= 2.5_stable9 | — |
| squid | squid | >= 0 < 2.5.9-9 | 2.5.9-9 |
| squid | squid | >= 0 < 2.5.9-9 | 2.5.9-9 |
| squid | squid | >= 0 < 2.5.9-9 | 2.5.9-9 |
| squid | squid | >= 0 < 2.5.9-9 | 2.5.9-9 |
CVSS provenance
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:P
osv6.4MEDIUM
vendor_debian6.4MEDIUM
vendor_redhat6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7j89-g7xj-9c6w: Squid 2
ghsa_unreviewed·2022-05-01
CVE-2005-1519 [MEDIUM] GHSA-7j89-g7xj-9c6w: Squid 2
Squid 2.5 STABLE9 and earlier, when the DNS client port is unfiltered and the environment does not prevent IP spoofing, allows remote attackers to spoof DNS lookups.
OSV
CVE-2005-1519: Squid 2
osv·2005-05-11·CVSS 6.4
CVE-2005-1519 [MEDIUM] CVE-2005-1519: Squid 2
Squid 2.5 STABLE9 and earlier, when the DNS client port is unfiltered and the environment does not prevent IP spoofing, allows remote attackers to spoof DNS lookups.
Ubuntu
Squid vulnerability
vendor_ubuntu·2005-05-18
CVE-2005-1519 Squid vulnerability
Title: Squid vulnerability
Summary: Squid vulnerability
It was discovered that Squid did not verify the validity of DNS server
responses. When Squid is started, it opens a DNS client UDP port whose
number is randomly assigned by the operating system. Unless your
network firewall is configured to accept DNS responses only from known
good nameservers, this vulnerability allowed users within the local
network to inject arbitrary DNS responses into Squid ("DNS spoofing").
This could be used to present different web pages to users from those
they actually requested.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
security flaw
vendor_redhat·2005-05-11·CVSS 6.4
CVE-2005-1519 [MEDIUM] security flaw
security flaw
Squid 2.5 STABLE9 and earlier, when the DNS client port is unfiltered and the environment does not prevent IP spoofing, allows remote attackers to spoof DNS lookups.
Debian
CVE-2005-1519: squid - Squid 2.5 STABLE9 and earlier, when the DNS client port is unfiltered and the en...
vendor_debian·2005·CVSS 6.4
CVE-2005-1519 [MEDIUM] CVE-2005-1519: squid - Squid 2.5 STABLE9 and earlier, when the DNS client port is unfiltered and the en...
Squid 2.5 STABLE9 and earlier, when the DNS client port is unfiltered and the environment does not prevent IP spoofing, allows remote attackers to spoof DNS lookups.
Scope: local
bookworm: resolved (fixed in 2.5.9-9)
bullseye: resolved (fixed in 2.5.9-9)
forky: resolved (fixed in 2.5.9-9)
sid: resolved (fixed in 2.5.9-9)
trixie: resolved (fixed in 2.5.9-9)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2005-1519 security flaw
bugzilla·2018-08-16·CVSS 6.4
CVE-2005-1519 [MEDIUM] CVE-2005-1519 security flaw
CVE-2005-1519 security flaw
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Discussion:
MITRE description:
Squid 2.5 STABLE9 and earlier, when the DNS client port is unfiltered and the environment does not prevent IP spoofing, allows remote attackers to spoof DNS lookups.
Bugzilla
Squid Multiple Vulnerabilities (CVE-2004-0541 CVE-2004-0832 CVE-2004-0918 CVE-2005-0094 CVE-2005-0095 CVE-2005-0096 CVE-2005-0097 CVE-2005-0446 CVE-2005-0626 CVE-2005-0718 CVE-1999-0710 CVE-2005-1345
bugzilla·2004-10-11·CVSS 7.5
CVE-2004-0541 [HIGH] Squid Multiple Vulnerabilities (CVE-2004-0541 CVE-2004-0832 CVE-2004-0918 CVE-2005-0094 CVE-2005-0095 CVE-2005-0096 CVE-2005-0097 CVE-2005-0446 CVE-2005-0626 CVE-2005-0718 CVE-1999-0710 CVE-2005-1345
Squid Multiple Vulnerabilities (CVE-2004-0541 CVE-2004-0832 CVE-2004-0918 CVE-2005-0094 CVE-2005-0095 CVE-2005-0096 CVE-2005-0097 CVE-2005-0446 CVE-2005-0626 CVE-2005-0718 CVE-1999-0710 CVE-2005-1345 CVE-2005-1519 CVE-2004-2479 CVE-2005-2794 CVE-2005-...
iDEFENSE reported on 2004-10-11 a vulnerability in the squid SNMP
module. This issue could lead to a potential DOS (it will restart
the server, dropping all open connections).
http://www.idefense.com/application/poi/display?id=152&type=vulnerabilities
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=135320
https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=135319
------- Additional Comments From [email protected] 2004-10-11 19:30:05 ----
Patch available here:
http://www1.uk.squid-cache.org/squid/Versions/v2/2
http://fedoranews.org/updates/FEDORA--.shtmlhttp://secunia.com/advisories/15294http://www.debian.org/security/2005/dsa-751http://www.redhat.com/archives/fedora-announce-list/2005-May/msg00025.htmlhttp://www.redhat.com/support/errata/RHSA-2005-489.htmlhttp://www.securityfocus.com/bid/13592http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE9-dns_queryhttp://www.vupen.com/english/advisories/2005/0521https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9976http://fedoranews.org/updates/FEDORA--.shtmlhttp://secunia.com/advisories/15294http://www.debian.org/security/2005/dsa-751http://www.redhat.com/archives/fedora-announce-list/2005-May/msg00025.htmlhttp://www.redhat.com/support/errata/RHSA-2005-489.htmlhttp://www.securityfocus.com/bid/13592http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE9-dns_queryhttp://www.vupen.com/english/advisories/2005/0521https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9976
2005-05-11
Published