Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2005-0241

The httpProcessReplyHeader function in http.c for Squid 2.5-STABLE7 and earlier does not properly set the debug context when it is handling "oversized" HTTP reply headers, which might allow remote attackers to poison the cache or bypass access controls based on header size.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.887
EPSS Ranking 99.5%
CVSS Severity
CVSS v2 Score 5.0
References
Products affected by CVE-2005-0241
  • Squid » Squid » Version: 2.5.stable1
    cpe:2.3:a:squid:squid:2.5.stable1
  • Squid » Squid » Version: 2.5.stable2
    cpe:2.3:a:squid:squid:2.5.stable2
  • Squid » Squid » Version: 2.5.stable3
    cpe:2.3:a:squid:squid:2.5.stable3
  • Squid » Squid » Version: 2.5.stable4
    cpe:2.3:a:squid:squid:2.5.stable4
  • Squid » Squid » Version: 2.5.stable5
    cpe:2.3:a:squid:squid:2.5.stable5
  • Squid » Squid » Version: 2.5.stable6
    cpe:2.3:a:squid:squid:2.5.stable6
  • Squid » Squid » Version: 2.5.stable7
    cpe:2.3:a:squid:squid:2.5.stable7


Contact Us

Shodan ® - All rights reserved