Madrid, March 7, 2005 - A patch has been released that fixes a vulnerability in version 2.5 -STABLE 7 to 9- of Squid (*), which could be used by a malicious user to disclose confidential information.
The security problem lies in a race window where Set-Cookie headers could leak to other users. This happens when the requested server relies on the Netscape Set-Cookie specification (obsolete since 1997).
More information about this vulnerability in Squid and the patch released is available at: http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE9-setcookie
(*) Squid: open code proxy server, which is widely used in Unix environments and is available for multiple platforms (from Linux, to Mac OS/X or Windows).
Oxygen3 24h-365d, by Panda Software
© Panda Software 2003
Back
Member of IVSZ

Member of SZEK

Acer Affinity Gold partner

Dell Registered Partner
![]()
OKI System Shinrai Partner

XEROX Viszonteladó

APC megbízható szállító

EATON Authorized Partner

Cisco partner

Symantec Software Partner

ESET Partner
![]()
FUJITSU partner

LENOVO Premium Partner

IBM Business Partner

PARTNERS: Computerworld.hu | GameStar.hu | PCWorld.hu | SG.hu | PC Guru | Hitel