Squid Proxy 2.4/2.5 - NULL URL Character Unauthorized Access

Related Vulnerabilities: CVE-2004-0189  
Publish Date: 01 Mar 2004
Author: Mitch Adair
                source: http://www.securityfocus.com/bid/9778/info

It has been reported that Squid Proxy may be prone to an unauthorized access vulnerability that may allow remote users to bypass access controls resulting in unauthorized access to attacker-specified resources. The vulnerability presents itself when a URI that is designed to access a specific location with a supplied username, contains '%00' characters. This sequence may be placed as part of the username value prior to the @ symbol in the malicious URI.

Squid Proxy versions 2.0 to 2.5 STABLE4 are reported to be prone to this vulnerability.
