From 3c6a572716c1460fb28004cc587056e49c22dd2f Mon Sep 17 00:00:00 2001 From: Remko Lodder Date: Mon, 20 Feb 2006 12:02:09 +0000 Subject: Document squid -- dns lookup spoofing. --- security/vuxml/vuln.xml | 28 ++++++++++++++++++++++++++++ 1 file changed, 28 insertions(+) (limited to 'security') diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index 1ce47c4a3c29..52f92c545938 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -34,6 +34,34 @@ Note: Please add new entries to the beginning of this file. --> + + squid -- dns lookup spoofing + + + squid + 2.5.10 + + + + +

The Squid team reports:

+
+

Malicious users may spoof DNS lookups if the DNS client UDP + port (random, assigned by OS at startup) is unfiltered and + your network is not protected from IP spoofing.

+
+ +
+ + CVE-2005-1519 + http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE9-dns_query + + + 2006-02-FIXME + 2006-02-20 + +
+ postgresql81-server -- SET ROLE privilege escalation -- cgit v1.2.3