Debian Squid vulnerabilities

144 known vulnerabilities affecting debian/squid.

Total CVEs
144
CISA KEV
0
Public exploits
9
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH39MEDIUM50LOW41

Vulnerabilities

Page 7 of 8
CVE-2005-0241MEDIUMCVSS 5.0fixed in squid 2.5.7-7 (bookworm)2005
CVE-2005-0241 [MEDIUM] CVE-2005-0241: squid - The httpProcessReplyHeader function in http.c for Squid 2.5-STABLE7 and earlier ... The httpProcessReplyHeader function in http.c for Squid 2.5-STABLE7 and earlier does not properly set the debug context when it is handling "oversized" HTTP reply headers, which might allow remote attackers to poison the cache or bypass access controls based on header size. Scope: local bookworm: resolved (fixed in 2.5.7-7) bullseye: resolved (fixed in 2.5.7-7) forky:
debian
CVE-2005-1519MEDIUMCVSS 6.4fixed in squid 2.5.9-9 (bookworm)2005
CVE-2005-1519 [MEDIUM] CVE-2005-1519: squid - Squid 2.5 STABLE9 and earlier, when the DNS client port is unfiltered and the en... Squid 2.5 STABLE9 and earlier, when the DNS client port is unfiltered and the environment does not prevent IP spoofing, allows remote attackers to spoof DNS lookups. Scope: local bookworm: resolved (fixed in 2.5.9-9) bullseye: resolved (fixed in 2.5.9-9) forky: resolved (fixed in 2.5.9-9) sid: resolved (fixed in 2.5.9-9) trixie: resolved (fixed in 2.5.9-9)
debian
CVE-2005-0095MEDIUMCVSS 5.0fixed in squid 2.5.7-4 (bookworm)2005
CVE-2005-0095 [MEDIUM] CVE-2005-0095: squid - The WCCP message parsing code in Squid 2.5.STABLE7 and earlier allows remote att... The WCCP message parsing code in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via malformed WCCP messages with source addresses that are spoofed to reference Squid's home router and invalid WCCP_I_SEE_YOU cache numbers. Scope: local bookworm: resolved (fixed in 2.5.7-4) bullseye: resolved (fixed in 2.5.7-4) forky: resolved
debian
CVE-2005-0718MEDIUMCVSS 5.0fixed in squid 2.5.8 (bookworm)2005
CVE-2005-0718 [MEDIUM] CVE-2005-0718: squid - Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of servi... Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (segmentation fault) by aborting the connection during a (1) PUT or (2) POST request, which causes Squid to access previously freed memory. Scope: local bookworm: resolved (fixed in 2.5.8) bullseye: resolved (fixed in 2.5.8) forky: resolved (fixed in 2.5.8) sid: resolved (fixed in 2.5.8
debian
CVE-2005-0097MEDIUMCVSS 5.0fixed in squid 2.5.7-4 (bookworm)2005
CVE-2005-0097 [MEDIUM] CVE-2005-0097: squid - The NTLM component in Squid 2.5.STABLE7 and earlier allows remote attackers to c... The NTLM component in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via a malformed NTLM type 3 message that triggers a NULL dereference. Scope: local bookworm: resolved (fixed in 2.5.7-4) bullseye: resolved (fixed in 2.5.7-4) forky: resolved (fixed in 2.5.7-4) sid: resolved (fixed in 2.5.7-4) trixie: resolved (fixed in 2.5
debian
CVE-2005-0446MEDIUMCVSS 5.0fixed in squid 2.5.8-3 (bookworm)2005
CVE-2005-0446 [MEDIUM] CVE-2005-0446: squid - Squid 2.5.STABLE8 and earlier allows remote attackers to cause a denial of servi... Squid 2.5.STABLE8 and earlier allows remote attackers to cause a denial of service (crash) via certain DNS responses regarding (1) Fully Qualified Domain Names (FQDN) in fqdncache.c or (2) IP addresses in ipcache.c, which trigger an assertion failure. Scope: local bookworm: resolved (fixed in 2.5.8-3) bullseye: resolved (fixed in 2.5.8-3) forky: resolved (fixed in 2.5
debian
CVE-2005-0094MEDIUMCVSS 5.0fixed in squid 2.5.7-4 (bookworm)2005
CVE-2005-0094 [MEDIUM] CVE-2005-0094: squid - Buffer overflow in the gopherToHTML function in the Gopher reply parser for Squi... Buffer overflow in the gopherToHTML function in the Gopher reply parser for Squid 2.5.STABLE7 and earlier allows remote malicious Gopher servers to cause a denial of service (crash) via crafted responses. Scope: local bookworm: resolved (fixed in 2.5.7-4) bullseye: resolved (fixed in 2.5.7-4) forky: resolved (fixed in 2.5.7-4) sid: resolved (fixed in 2.5.7-4) trixie:
debian
CVE-2005-2917MEDIUMCVSS 5.0fixed in squid 2.5.10-7 (bookworm)2005
CVE-2005-2917 [MEDIUM] CVE-2005-2917: squid - Squid 2.5.STABLE10 and earlier, while performing NTLM authentication, does not p... Squid 2.5.STABLE10 and earlier, while performing NTLM authentication, does not properly handle certain request sequences, which allows attackers to cause a denial of service (daemon restart). Scope: local bookworm: resolved (fixed in 2.5.10-7) bullseye: resolved (fixed in 2.5.10-7) forky: resolved (fixed in 2.5.10-7) sid: resolved (fixed in 2.5.10-7) trixie: resolved
debian
CVE-2005-0626LOWCVSS 2.6fixed in squid 2.5.9-2 (bookworm)2005
CVE-2005-0626 [LOW] CVE-2005-0626: squid - Race condition in Squid 2.5.STABLE7 to 2.5.STABLE9, when using the Netscape Set-... Race condition in Squid 2.5.STABLE7 to 2.5.STABLE9, when using the Netscape Set-Cookie recommendations for handling cookies in caches, may cause Set-Cookie headers to be sent to other users, which allows attackers to steal the related cookies. Scope: local bookworm: resolved (fixed in 2.5.9-2) bullseye: resolved (fixed in 2.5.9-2) forky: resolved (fixed in 2.5.9-2) sid:
debian
CVE-2005-3322LOWCVSS 5.02005
CVE-2005-3322 [MEDIUM] CVE-2005-3322: squid - Unspecified vulnerability in Squid on SUSE Linux 9.0 allows remote attackers to ... Unspecified vulnerability in Squid on SUSE Linux 9.0 allows remote attackers to cause a denial of service (crash) via HTTPs (SSL). Scope: local bookworm: resolved bullseye: resolved forky: resolved sid: resolved trixie: resolved
debian
CVE-2005-3258LOWCVSS 5.02005
CVE-2005-3258 [MEDIUM] CVE-2005-3258: squid - The rfc1738_do_escape function in ftp.c for Squid 2.5 STABLE11 and earlier allow... The rfc1738_do_escape function in ftp.c for Squid 2.5 STABLE11 and earlier allows remote FTP servers to cause a denial of service (segmentation fault) via certain "odd" responses. Scope: local bookworm: resolved bullseye: resolved forky: resolved sid: resolved trixie: resolved
debian
CVE-2004-0541CRITICALCVSS 10.0PoCfixed in squid 2.5.5-5 (bookworm)2004
CVE-2004-0541 [CRITICAL] CVE-2004-0541: squid - Buffer overflow in the ntlm_check_auth (NTLM authentication) function for Squid ... Buffer overflow in the ntlm_check_auth (NTLM authentication) function for Squid Web Proxy Cache 2.5.x and 3.x, when compiled with NTLM handlers enabled, allows remote attackers to execute arbitrary code via a long password ("pass" variable). Scope: local bookworm: resolved (fixed in 2.5.5-5) bullseye: resolved (fixed in 2.5.5-5) forky: resolved (fixed in 2.5.5-5) si
debian
CVE-2004-0189HIGHCVSS 7.5PoCfixed in squid 2.5.5-1 (bookworm)2004
CVE-2004-0189 [HIGH] CVE-2004-0189: squid - The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote at... The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL ("%00") character, which causes Squid to use only a portion of the requested URL when comparing it against the access control lists. Scope: local bookworm: resolved (fixed in 2.5.5-1) bullseye: resolved (fixed in 2.5.5-1) forky: resolved
debian
CVE-2004-2480MEDIUMCVSS 5.0PoCfixed in squid 2.5 (bookworm)2004
CVE-2004-2480 [MEDIUM] CVE-2004-2480: squid - Squid Web Proxy Cache 2.3.STABLE5 allows remote attackers to bypass security con... Squid Web Proxy Cache 2.3.STABLE5 allows remote attackers to bypass security controls and access arbitrary websites via "@@" sequences in a URL within Internet Explorer. Scope: local bookworm: resolved (fixed in 2.5) bullseye: resolved (fixed in 2.5) forky: resolved (fixed in 2.5) sid: resolved (fixed in 2.5) trixie: resolved (fixed in 2.5)
debian
CVE-2004-0832MEDIUMCVSS 5.0fixed in squid 2.5.6-8 (bookworm)2004
CVE-2004-0832 [MEDIUM] CVE-2004-0832: squid - The (1) ntlm_fetch_string and (2) ntlm_get_string functions in Squid 2.5.6 and e... The (1) ntlm_fetch_string and (2) ntlm_get_string functions in Squid 2.5.6 and earlier, with NTLM authentication enabled, allow remote attackers to cause a denial of service (application crash) via an NTLMSSP packet that causes a negative value to be passed to memcpy. Scope: local bookworm: resolved (fixed in 2.5.6-8) bullseye: resolved (fixed in 2.5.6-8) forky: resol
debian
CVE-2004-2654MEDIUMCVSS 5.0fixed in squid 2.5.6 (bookworm)2004
CVE-2004-2654 [MEDIUM] CVE-2004-2654: squid - The clientAbortBody function in client_side.c in Squid Web Proxy Cache before 2.... The clientAbortBody function in client_side.c in Squid Web Proxy Cache before 2.6 STABLE6 allows remote attackers to cause a denial of service (segmentation fault) via unspecified vectors that trigger a null dereference. NOTE: in a followup advisory, a researcher claimed that the issue was a buffer overflow that was not fixed in STABLE6. However, the vendor's bug repo
debian
CVE-2004-0918MEDIUMCVSS 5.0fixed in squid 2.5.7 (bookworm)2004
CVE-2004-0918 [MEDIUM] CVE-2004-0918: squid - The asn_parse_header function (asn1.c) in the SNMP module for Squid Web Proxy Ca... The asn_parse_header function (asn1.c) in the SNMP module for Squid Web Proxy Cache before 2.4.STABLE7 allows remote attackers to cause a denial of service (server restart) via certain SNMP packets with negative length fields that trigger a memory allocation error. Scope: local bookworm: resolved (fixed in 2.5.7) bullseye: resolved (fixed in 2.5.7) forky: resolved (fi
debian
CVE-2004-2479MEDIUMCVSS 5.0fixed in squid 2.5.8 (bookworm)2004
CVE-2004-2479 [MEDIUM] CVE-2004-2479: squid - Squid Web Proxy Cache 2.5 might allow remote attackers to obtain sensitive infor... Squid Web Proxy Cache 2.5 might allow remote attackers to obtain sensitive information via URLs containing invalid hostnames that cause DNS operations to fail, which results in references to previously used error messages. Scope: local bookworm: resolved (fixed in 2.5.8) bullseye: resolved (fixed in 2.5.8) forky: resolved (fixed in 2.5.8) sid: resolved (fixed in 2.5.8
debian
CVE-2002-0714HIGHCVSS 7.5fixed in squid 2.4.6 (bookworm)2002
CVE-2002-0714 [HIGH] CVE-2002-0714: squid - FTP proxy in Squid before 2.4.STABLE6 does not compare the IP addresses of contr... FTP proxy in Squid before 2.4.STABLE6 does not compare the IP addresses of control and data connections with the FTP server, which allows remote attackers to bypass firewall rules or spoof FTP server responses. Scope: local bookworm: resolved (fixed in 2.4.6) bullseye: resolved (fixed in 2.4.6) forky: resolved (fixed in 2.4.6) sid: resolved (fixed in 2.4.6) trixie: reso
debian
CVE-2002-0713HIGHCVSS 7.5fixed in squid 2.4.6-2 (bookworm)2002
CVE-2002-0713 [HIGH] CVE-2002-0713: squid - Buffer overflows in Squid before 2.4.STABLE6 allow remote attackers to cause a d... Buffer overflows in Squid before 2.4.STABLE6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code (1) via the MSNT auth helper (msnt_auth) when using denyusers or allowusers files, (2) via the gopher client, or (3) via the FTP server directory listing parser when HTML output is generated. Scope: local bookworm: resolved (fixed
debian
Debian Squid vulnerabilities | cvebase