SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2005-0174

Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache or conduct certain attacks via headers that do not follow the HTTP specification, including (1) multiple Content-Length headers, (2) carriage return (CR) characters that are not…

MEDIUM 5.0EPSS 50.5%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 50.5%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache or conduct certain attacks via headers that do not follow the HTTP specification, including (1) multiple Content-Length headers, (2) carriage return (CR) characters that are not part of a CRLF pair, and (3) header names containing whitespace characters.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS
50.49% probability · 99th percentile
CISA KEV
Not listed
Affected
squid/squid
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.