Orange Business Services
Vigil@nce Vigil@nce Vigil@nce
we track for your security since 1999
  home presentation vulnerabilities documentation contact  
subscriber area subscriber area
free access free access
The Vigil@nce team watches vulnerabilities impacting your computers, and then offers solutions, a database and tools to correct them.
recent vulnerabilities recent vulnerabilities
tracked products tracked products
RSS feed RSS feed
vulnerable product
Vulnerabilities of Squid

Squid vulnerability: buffer overflow via httpMakeVaryMark
An attacker, who is located on both sides of the Squid proxy, can use the HTTP Vary header, in order to trigger a buffer overflow, leading to a denial of service, and possibly to code execution.

Squid vulnerability: memory leaks in cachemgr.cgi
An attacker can send inconsistent requests to cachemgr.cgi, in order to make it allocate too much memory and eventually halt.

Squid vulnerability: obtaining users' passwords
An attacker can create a malicious web site, and invite a Squid user to connect to this site, in order to obtain his basic authentication data.

Squid vulnerability: denial of service via FTP
A malicious FTP server can interrupt a session, in order to stop Squid.

Squid vulnerability: buffer overflow of gopherToHTML
An attacker can return a malicious Gopher reply, in order to create a buffer overflow in the gopherToHTML() function.

Display other vulnerabilities of Squid described by Vigil@nce...

Display information about Squid:



















Copyright 1999-2013 Vigil@nce. Vigil@nce is a service from Orange Business Services. Site map. Legal notice. Version française