CVE-1999-1481: Medium severity National Science Foundation Squid Web Proxy vulnerability
Squid 2.2.STABLE5 and below, when using external authentication, allows attackers to bypass access controls via a newline in the user/password pair.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable external authentication (external auth helpers) until a fixed Squid release is available to prevent access-control bypass via newline in user/password pairs.
Squid Web Proxy Cache external authentication = disabled
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1481?
CVE-1999-1481 is considered a critical vulnerability as it allows attackers to bypass access control measures.
How do I fix CVE-1999-1481?
To fix CVE-1999-1481, upgrade to a version of Squid that is above 2.2.STABLE5.
What versions of Squid are affected by CVE-1999-1481?
CVE-1999-1481 affects Squid versions 2.2.STABLE5 and earlier, as well as versions 1.0, 1.1, and 2.1.
Can CVE-1999-1481 be exploited remotely?
Yes, CVE-1999-1481 can be exploited remotely by attackers leveraging external authentication with specially crafted user/password inputs.
What type of attacks can be performed using CVE-1999-1481?
CVE-1999-1481 can be exploited to gain unauthorized access to resources restricted by access controls.