← All CVEs

CVE-2005-0241

medium · 5

The httpProcessReplyHeader function in http.c for Squid 2.5-STABLE7 and earlier does not properly set the debug context when it is handling "oversized" HTTP reply headers, which might allow remote attackers to poison the cache or bypass access controls based on header size.

5
CVSS
69.7%
EPSS (exploit prob.)
99th
EPSS percentile
2005-05-02
Published

AV:N/AC:L/Au:N/C:N/I:P/A:N

Affected products

VendorProductAffected versions
squidsquid2.5.stable1
squidsquid2.5.stable2
squidsquid2.5.stable3
squidsquid2.5.stable4
squidsquid2.5.stable5
squidsquid2.5.stable6
squidsquid2.5.stable7

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2005-0241