← Back

CVE-2005-0241

nvd nist
Published: May 2, 2005Modified: Apr 16, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:P/A:N
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

The httpProcessReplyHeader function in http.c for Squid 2.5-STABLE7 and earlier does not properly set the debug context when it is handling "oversized" HTTP reply headers, which might allow remote attackers to poison the cache or bypass access controls based on header size.

Affected (7)

Products: Squid: Squid
1 product
Squid
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Squid
Version 2.5.stable1
Version 2.5.stable2
Version 2.5.stable3
Version 2.5.stable4
Version 2.5.stable5
Version 2.5.stable6
Version 2.5.stable7

References (26)

Source: security@debian.org
Source: security@debian.org
PatchThird Party AdvisoryUS Government Resource
Source: security@debian.org
PatchVendor Advisory
Source: security@debian.org
PatchVendor Advisory
Source: security@debian.org
PatchVendor Advisory
Source: security@debian.org
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.