FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2004-0189

This CVE name corresponds to:

Entered Topic
2004-03-26 squid ACL bypass due to URL decoding bug

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type CVE Entry
Name CVE-2004-0189

Description

The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL ("%00") characterm, which causes Squid to use only a portion of the requested URL when comparing it against the access control lists.

References

Source Reference
CONFIRM http://www.squid-cache.org/Advisories/SQUID-2004_1.txt
CONECTIVA CLA-2004:838
DEBIAN DSA-474
GENTOO GLSA-200403-11
MANDRAKE MDKSA-2004:025
REDHAT RHSA-2004:133
REDHAT RHSA-2004:134
SCO SCOSA-2005.16
SGI 20040404-01-U
BUGTRAQ 20040401 [OpenPKG-SA-2004.008] OpenPKG Security Advisory (squid)
BID 9778
XF squid-urlregex-acl-bypass(15366)
OSVDB 5916
OVAL oval:org.mitre.oval:def:877
OVAL oval:org.mitre.oval:def:941