CVE-2005-0174
Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache or conduct certain attacks via headers that do not follow the HTTP specification, including (1) multiple Content-Length headers, (2) carriage return (CR) characters that are not…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 50.5%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache or conduct certain attacks via headers that do not follow the HTTP specification, including (1) multiple Content-Length headers, (2) carriage return (CR) characters that are not part of a CRLF pair, and (3) header names containing whitespace characters.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 50.49% probability · 99th percentile
- CISA KEV
- Not listed
- Affected
- squid/squid
- Source
- cve@mitre.org
References
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000931Vendor Advisory
- http://fedoranews.org/updates/FEDORA--.shtml
- http://marc.info/?l=bugtraq&m=110780531820947&w=2
- http://www.kb.cert.org/vuls/id/768702Third Party Advisory, US Government Resource
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:034
- http://www.novell.com/linux/security/advisories/2005_06_squid.htmlVendor Advisory
- http://www.redhat.com/archives/fedora-announce-list/2005-May/msg00025.html
- http://www.redhat.com/support/errata/RHSA-2005-060.htmlPatch
- http://www.redhat.com/support/errata/RHSA-2005-061.htmlPatch
- http://www.securityfocus.com/bid/12412
- http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-header_parsingVendor Advisory
- http://www3.br.squid-cache.org/Advisories/SQUID-2005_4.txt
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10656
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000931Vendor Advisory
- http://fedoranews.org/updates/FEDORA--.shtml
- http://marc.info/?l=bugtraq&m=110780531820947&w=2
- http://www.kb.cert.org/vuls/id/768702Third Party Advisory, US Government Resource
- http://www.mandriva.com/security/advisories?name=MDKSA-2005:034
- http://www.novell.com/linux/security/advisories/2005_06_squid.htmlVendor Advisory
- http://www.redhat.com/archives/fedora-announce-list/2005-May/msg00025.html
- http://www.redhat.com/support/errata/RHSA-2005-060.htmlPatch
- http://www.redhat.com/support/errata/RHSA-2005-061.htmlPatch
- http://www.securityfocus.com/bid/12412
- http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-header_parsingVendor Advisory
- http://www3.br.squid-cache.org/Advisories/SQUID-2005_4.txt
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10656
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.