10

CVE-2005-0194

Squid 2.5, when processing the configuration file, parses empty Access Control Lists (ACLs), including proxy_auth ACLs without defined auth schemes, in a way that effectively removes arguments, which could allow remote attackers to bypass intended ACLs if the administrator ignores the parser warnings.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SquidSquid Version2.0.patch1
SquidSquid Version2.0.patch2
SquidSquid Version2.0.pre1
SquidSquid Version2.0.release
SquidSquid Version2.1.patch1
SquidSquid Version2.1.patch2
SquidSquid Version2.1.pre1
SquidSquid Version2.1.pre3
SquidSquid Version2.1.pre4
SquidSquid Version2.1.release
SquidSquid Version2.2.devel3
SquidSquid Version2.2.devel4
SquidSquid Version2.2.pre1
SquidSquid Version2.2.pre2
SquidSquid Version2.2.stable1
SquidSquid Version2.2.stable2
SquidSquid Version2.2.stable3
SquidSquid Version2.2.stable4
SquidSquid Version2.2.stable5
SquidSquid Version2.3.devel2
SquidSquid Version2.3.devel3
SquidSquid Version2.3.stable1
SquidSquid Version2.3.stable2
SquidSquid Version2.3.stable3
SquidSquid Version2.3.stable4
SquidSquid Version2.3.stable5
SquidSquid Version2.4.stable1
SquidSquid Version2.4.stable2
SquidSquid Version2.4.stable3
SquidSquid Version2.4.stable4
SquidSquid Version2.4.stable6
SquidSquid Version2.4.stable7
SquidSquid Version2.5.stable1
SquidSquid Version2.5.stable2
SquidSquid Version2.5.stable3
SquidSquid Version2.5.stable4
SquidSquid Version2.5.stable5
SquidSquid Version2.5.stable6
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.01% 0.75
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C