2.6
CVSSv2

CVE-2005-0626

Published: 08/03/2005 Updated: 03/10/2018
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N

Vulnerability Summary

Race condition in Squid 2.5.STABLE7 to 2.5.STABLE9, when using the Netscape Set-Cookie recommendations for handling cookies in caches, may cause Set-Cookie headers to be sent to other users, which allows malicious users to steal the related cookies.

Vulnerable Product Search on Vulmon Subscribe to Product

squid squid 2.5.stable6

squid squid 2.5.stable7

squid squid 2.5.stable5

Vendor Advisories

Synopsis squid security update Type/Severity Security Advisory: Low Topic An updated squid package that fixes several security issues is now availableThis update has been rated as having low security impact by the Red HatSecurity Response Team Description Squid is a full-featured Web prox ...
A race condition was discovered in the handling of “Set-Cookie” headers If the obsolete Netscape recommendation was used for handling cookies in the cache, it was possible for an attacker to steal the cookies of other users ...