Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2005-0194

Опубликовано: 02 мая 2005
Источник: nvd
CVSS2: 10
EPSS Низкий

Описание

Squid 2.5, when processing the configuration file, parses empty Access Control Lists (ACLs), including proxy_auth ACLs without defined auth schemes, in a way that effectively removes arguments, which could allow remote attackers to bypass intended ACLs if the administrator ignores the parser warnings.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:squid:squid:2.0.patch1:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.0.patch2:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.0.pre1:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.0.release:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.1.patch1:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.1.patch2:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.1.pre1:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.1.pre3:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.1.pre4:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.1.release:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.2.devel3:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.2.devel4:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.2.pre1:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.2.pre2:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.2.stable1:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.2.stable2:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.2.stable3:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.2.stable4:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.2.stable5:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.3.devel2:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.3.devel3:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.3.stable1:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.3.stable2:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.3.stable3:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.3.stable4:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.3.stable5:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.4.stable1:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.4.stable2:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.4.stable3:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.4.stable4:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.4.stable6:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.4.stable7:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.5.stable1:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.5.stable2:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.5.stable3:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.5.stable4:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.5.stable5:*:*:*:*:*:*:*
cpe:2.3:a:squid:squid:2.5.stable6:*:*:*:*:*:*:*

EPSS

Процентиль: 76%
0.01009
Низкий

10 Critical

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

ubuntu
больше 20 лет назад

Squid 2.5, when processing the configuration file, parses empty Access Control Lists (ACLs), including proxy_auth ACLs without defined auth schemes, in a way that effectively removes arguments, which could allow remote attackers to bypass intended ACLs if the administrator ignores the parser warnings.

debian
больше 20 лет назад

Squid 2.5, when processing the configuration file, parses empty Access ...

github
больше 3 лет назад

Squid 2.5, when processing the configuration file, parses empty Access Control Lists (ACLs), including proxy_auth ACLs without defined auth schemes, in a way that effectively removes arguments, which could allow remote attackers to bypass intended ACLs if the administrator ignores the parser warnings.

EPSS

Процентиль: 76%
0.01009
Низкий

10 Critical

CVSS2

Дефекты

NVD-CWE-Other