CVE-2005-0094: Buffer Overflow
Buffer overflow in the gopherToHTML function in the Gopher reply parser for Squid 2.5.STABLE7 and earlier allows remote malicious Gopher servers to cause a denial of service (crash) via crafted responses.
Other sources
Flaw bug created to hold information about an old flaw we knew something about. For more details see the MITRE CVE description.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-0094?
CVE-2005-0094 is classified as a medium severity vulnerability due to its potential to cause denial of service.
How do I fix CVE-2005-0094?
To fix CVE-2005-0094, you should upgrade to a more recent version of the Squid Web Proxy Cache that is not affected by this vulnerability.
Which versions of Squid are affected by CVE-2005-0094?
CVE-2005-0094 affects Squid versions 2.5.STABLE7 and earlier, including various patch and stable releases.
What type of attack can be executed using CVE-2005-0094?
CVE-2005-0094 can be exploited by remote malicious Gopher servers to induce a denial of service attack, resulting in a crash.
What component of Squid is vulnerable in CVE-2005-0094?
The vulnerability in CVE-2005-0094 lies in the gopherToHTML function within the Gopher reply parser.