5

CVE-2005-0241

The httpProcessReplyHeader function in http.c for Squid 2.5-STABLE7 and earlier does not properly set the debug context when it is handling "oversized" HTTP reply headers, which might allow remote attackers to poison the cache or bypass access controls based on header size.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SquidSquid Version2.5.stable1
SquidSquid Version2.5.stable2
SquidSquid Version2.5.stable3
SquidSquid Version2.5.stable4
SquidSquid Version2.5.stable5
SquidSquid Version2.5.stable6
SquidSquid Version2.5.stable7
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 88.66% 0.994
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:P/A:N