VulnerabilityModified
CVE-2004-2479
Squid Web Proxy Cache 2.5 might allow remote attackers to obtain sensitive information via URLs containing invalid hostnames that cause DNS operations to fail, which results in references to previously used error messages.
MEDIUM 5.0EPSS 2.08%
Does this matter?
Lower severity and a low EPSS score (2.08%). Track it; it rarely justifies an emergency change on its own.
Description
Squid Web Proxy Cache 2.5 might allow remote attackers to obtain sensitive information via URLs containing invalid hostnames that cause DNS operations to fail, which results in references to previously used error messages.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.08% probability · 80th percentile
- CISA KEV
- Not listed
- Affected
- national science foundation/squid web proxy cache
- Source
- cve@mitre.org
References
- http://fedoranews.org/updates/FEDORA--.shtml
- http://secunia.com/advisories/13408Patch, Vendor Advisory
- http://secunia.com/advisories/16977
- http://securitytracker.com/id?1012466Patch
- http://www.osvdb.org/12282
- http://www.redhat.com/support/errata/RHSA-2005-766.html
- http://www.securityfocus.com/bid/11865Patch
- http://www.squid-cache.org/bugs/show_bug.cgi?id=1143Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18406
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9711
- http://fedoranews.org/updates/FEDORA--.shtml
- http://secunia.com/advisories/13408Patch, Vendor Advisory
- http://secunia.com/advisories/16977
- http://securitytracker.com/id?1012466Patch
- http://www.osvdb.org/12282
- http://www.redhat.com/support/errata/RHSA-2005-766.html
- http://www.securityfocus.com/bid/11865Patch
- http://www.squid-cache.org/bugs/show_bug.cgi?id=1143Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18406
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9711
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.