7.5
CVSSv2

CVE-2005-1345

Published: 02/05/2005 Updated: 11/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Squid 2.5.STABLE9 and previous versions does not trigger a fatal error when it identifies missing or invalid ACLs in the http_access configuration, which could lead to less restrictive ACLs than intended by the administrator.

Vulnerable Product Search on Vulmon Subscribe to Product

squid squid 2.5.stable6

squid squid 2.5.stable7

squid squid 2.5.stable1

squid squid 2.5.stable2

squid squid 2.5.stable3

squid squid 2.5.stable4

squid squid 2.5.stable5

squid squid 2.5.stable8

squid squid 2.5.stable9

Vendor Advisories

Synopsis squid security update Type/Severity Security Advisory: Low Topic An updated squid package that fixes several security issues is now availableThis update has been rated as having low security impact by the Red HatSecurity Response Team Description Squid is a full-featured Web prox ...
Michael Bhola discovered that errors in the http_access configuration, in particular missing or invalid ACLs, did not cause a fatal error This could lead to wider access permissions than intended by the administrator ...
Michael Bhola discovered a bug in Squid, the popular WWW proxy cache Squid does not trigger a fatal error when it identifies missing or invalid ACLs in the http_access configuration, which could lead to less restrictive ACLs than intended by the administrator For the stable distribution (woody) this problem has been fixed in version 246-2woody8 ...