VDB
CVE-2005-0241
CVE-2005-0241
PUBLISHED
CVSS 5 MEDIUM
The httpProcessReplyHeader function in http.c for Squid 2.5-STABLE7 and earlier does not properly set the debug context when it is handling "oversized" HTTP reply headers, which might allow remote attackers to poison the cache or bypass access controls based on header size.
EPSS 86.22% · 99.4th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
86.22%
99.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| squid | squid | 2.5.stable3, 2.5.stable4, 2.5.stable5 |
| n/a | n/a | * |
Timeline
- Feb 8, 2005 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 1, 2022 CVE Updated
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- 14091 third-party-advisory
- VU#823350 third-party-advisory
- 12412 vdb
- http://www.squid-cache.org/bugs/show_bug.cgi?id=1216 url
- oval:org.mitre.oval:def:10998 vdb
- FLSA-2006:152809 vendor-advisory
- RHSA-2005:061 vendor-advisory
- squid-http-cache-poisoning(19060) vdb
- CLA-2005:931 vendor-advisory
- http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-oversize_reply_headers url
- SUSE-SA:2005:006 vendor-advisory
- RHSA-2005:060 vendor-advisory
- http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-oversize_reply_headers.patch url
- https://nvd.nist.gov/vuln/detail/CVE-2005-0241 advisory