VDB
CVE-2005-0241
CVE-2005-0241
PUBLISHED
CVSS 5 MEDIUM
The httpProcessReplyHeader function in http.c for Squid 2.5-STABLE7 and earlier does not properly set the debug context when it is handling "oversized" HTTP reply headers, which might allow remote attackers to poison the cache or bypass access controls based on header size.
EPSS 69.66% · 99.3th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
69.66%
99.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| squid | squid | 2.5.stable3, 2.5.stable4, 2.5.stable5 |
| n/a | n/a | * |
Timeline
- Feb 8, 2005 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- oval:org.mitre.oval:def:10998 vdb
- http://www.squid-cache.org/bugs/show_bug.cgi?id=1216 url
- FLSA-2006:152809 vendor-advisory
- RHSA-2005:061 vendor-advisory
- CLA-2005:931 vendor-advisory
- SUSE-SA:2005:006 vendor-advisory
- http://www.kb.cert.org/vuls/id/823350 patch
- http://www.securityfocus.com/bid/12412 technical
- http://secunia.com/advisories/14091 technical
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19060 technical
- https://nvd.nist.gov/vuln/detail/CVE-2005-0241 advisory
- http://www.redhat.com/support/errata/RHSA-2005-060.html url
- http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-oversize_reply_headers url
- http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-oversize_reply_headers.patch url