← Back

CVE-2005-0194

nvd nist
Published: May 2, 2005Modified: Apr 16, 2026

JSON object

Loading...
10.0
Vector
AV:N/AC:L/Au:N/C:C/I:C/A:C
Exploitability: 10.0 / Impact: 10.0
Source: NVD

Description

Squid 2.5, when processing the configuration file, parses empty Access Control Lists (ACLs), including proxy_auth ACLs without defined auth schemes, in a way that effectively removes arguments, which could allow remote attackers to bypass intended ACLs if the administrator ignores the parser warnings.

Affected (38)

Products: Squid: Squid
1 product
Squid
Configuration A
38 vulnerable
Vulnerable SoftwareAffected Versions
Squid
Version 2.0.patch1
Version 2.0.patch2
Version 2.0.pre1
Version 2.0.release
Version 2.1.patch1
Version 2.1.patch2
Version 2.1.pre1
Version 2.1.pre3
Version 2.1.pre4
Version 2.1.release
Version 2.2.devel3
Version 2.2.devel4
Version 2.2.pre1
Version 2.2.pre2
Version 2.2.stable1
Version 2.2.stable2
Version 2.2.stable3
Version 2.2.stable4
Version 2.2.stable5
Version 2.3.devel2
Version 2.3.devel3
Version 2.3.stable1
Version 2.3.stable2
Version 2.3.stable3
Version 2.3.stable4
Version 2.3.stable5
Version 2.4.stable1
Version 2.4.stable2
Version 2.4.stable3
Version 2.4.stable4
Version 2.4.stable6
Version 2.4.stable7
Version 2.5.stable1
Version 2.5.stable2
Version 2.5.stable3
Version 2.5.stable4
Version 2.5.stable5
Version 2.5.stable6

References (16)

Source: cve@mitre.org
PatchVendor Advisory
Source: cve@mitre.org
PatchThird Party AdvisoryUS Government Resource
Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.