CVE-2001-1030
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD
Description
Squid before 2.3STABLE5 in HTTP accelerator mode does not enable access control lists (ACLs) when the httpd_accel_host and http_accel_with_proxy off settings are used, which allows attackers to bypass the ACLs and conduct unauthorized activities such as port scanning.
Affected (15)
Products: Caldera: Openlinux Server · Immunix: Immunix · Mandrakesoft: Mandrake Single Network Firewall, Mandrake Linux, Mandrake Linux Corporate Server · +3 more
Show all products
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.1 | |
| Version 6.2 | |
| Version 7.2 | |
| Version 2.3stable3 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.1 | |
| Version 1.0.1 | |
| Version 7.0 | |
| Version 1.01 |
References (14)
Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
Source: cve@mitre.org
Source: cve@mitre.org
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.