Squid HTTP Request Smuggling


Description   A vulnerability has been identified in Squid, which could be exploited by malicious people to conduct smuggling attacks. This flaw is due to an error when handling HTTP requests containing both "Transfer-Encoding: chunked" and "Content-Length" headers, which could allow the bypass of Web application firewall protection or lead to cross site scripting attacks.
     
Vulnerable Products   Vulnerable Software:
Squid 2.5.STABLE7 and prior
     
Solution   Upgrade to version 2.5.STABLE8 : http://www.squid-cache.org/
     
CVE  
     
References  
     
Vulnerability Manager Detection   No
     
IPS Protection  
ASQ Engine alarm Available Since
HTTP Request Smuggling : HTTP command found in header
3.2.0
HTTP Request Smuggling : Content-Length and Transfer-Encoding: chunked fields in header
3.2.0
HTTP Request Smuggling : suspicious syntax using HTTP keyword
3.2.0
HTTP Request Smuggling : multiple Content-Length fields
3.2.0
     


 
 
 
 
 Risk level 
Moderate 

 Vulnerability First Public Report Date 
2005-06-30 

 Target Type 
Server 

 Possible exploit 
Local & Remote