5
CVSSv2

CVE-2005-0174

Published: 07/02/2005 Updated: 11/10/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Squid 2.5 up to 2.5.STABLE7 allows remote malicious users to poison the cache or conduct certain attacks via headers that do not follow the HTTP specification, including (1) multiple Content-Length headers, (2) carriage return (CR) characters that are not part of a CRLF pair, and (3) header names containing whitespace characters.

Vulnerable Product Search on Vulmon Subscribe to Product

squid squid 2.5.6

squid squid 2.5_.stable1

squid squid 2.5_.stable3

squid squid 2.5.stable3

squid squid 2.5.stable4

squid squid 2.5.stable5

squid squid 2.5_.stable6

squid squid 2.5_stable3

squid squid 2.5.stable6

squid squid 2.5.stable7

squid squid 2.5_stable4

squid squid 2.5_stable9

squid squid 2.5.stable1

squid squid 2.5.stable2

squid squid 2.5_.stable4

squid squid 2.5_.stable5

Vendor Advisories

A possible authentication bypass was discovered in the LDAP authentication backend LDAP ignores leading and trailing whitespace in search filters This could possibly be abused to bypass explicit access controls or confuse accounting when using several variants of the login name (CAN-2005-0173) ...
Synopsis squid security update Type/Severity Security Advisory: Important Topic An updated Squid package that fixes several security issues is now available Description Squid is a full-featured Web proxy cacheA buffer overflow flaw was found in the Gopher relay parser This bugcould allow ...
Synopsis squid security update Type/Severity Security Advisory: Important Topic An updated Squid package that fixes several security issues is now availableThis update has been rated as having important security impact by the Red HatSecurity Response Team Description Squid is a full-featu ...