Squid 2.2.STABLE5 and below, when using external authentication, allows attackers to bypass access controls via a newline in the user/password pair.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/33295 | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/3433 | vdb entry |
http://www.squid-cache.org/Versions/v2/2.2/bugs/ | patch vendor advisory |
http://www.securityfocus.com/bid/741 | patch vendor advisory vdb entry exploit |