Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2005-0174

Опубликовано: 07 фев. 2005
Источник: nvd
CVSS2: 5
EPSS Высокий

Описание

Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache or conduct certain attacks via headers that do not follow the HTTP specification, including (1) multiple Content-Length headers, (2) carriage return (CR) characters that are not part of a CRLF pair, and (3) header names containing whitespace characters.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:squid:squid:2.5.6:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.5.stable1:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.5.stable2:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.5.stable3:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.5.stable4:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.5.stable5:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.5.stable6:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.5.stable7:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.5_.stable1:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.5_.stable3:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.5_.stable4:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.5_.stable5:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.5_.stable6:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.5_stable3:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.5_stable4:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.5_stable9:*:*:*:*:*:*:*

EPSS

Процентиль: 99%
0.83332
Высокий

5 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

ubuntu
около 21 года назад

Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache or conduct certain attacks via headers that do not follow the HTTP specification, including (1) multiple Content-Length headers, (2) carriage return (CR) characters that are not part of a CRLF pair, and (3) header names containing whitespace characters.

redhat
около 21 года назад

Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache or conduct certain attacks via headers that do not follow the HTTP specification, including (1) multiple Content-Length headers, (2) carriage return (CR) characters that are not part of a CRLF pair, and (3) header names containing whitespace characters.

debian
около 21 года назад

Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cach ...

github
почти 4 года назад

Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache or conduct certain attacks via headers that do not follow the HTTP specification, including (1) multiple Content-Length headers, (2) carriage return (CR) characters that are not part of a CRLF pair, and (3) header names containing whitespace characters.

EPSS

Процентиль: 99%
0.83332
Высокий

5 Medium

CVSS2

Дефекты

NVD-CWE-Other