CVE-1999-1273: High severity National Science Foundation Squid Web Proxy vulnerability
Squid Internet Object Cache 1.1.20 allows users to bypass access control lists (ACLs) by encoding the URL with hexadecimal escape sequences.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Squid Web Proxy Cache 1.1.20from your environment.Uninstall or stop running Squid Web Proxy Cache version 1.1.20 (it is vulnerable to ACL bypass via hexadecimal-encoded URLs).
- Operational
Do not deploy or operate Squid Web Proxy Cache 1.1.20; remove or replace instances running this version until a vendor-supplied fixed version is available.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1273?
CVE-1999-1273 is classified as a high severity vulnerability due to its ability to bypass access control lists and potentially expose sensitive data.
How do I fix CVE-1999-1273?
To fix CVE-1999-1273, upgrade the Squid Web Proxy Cache to a version that addresses this vulnerability, preferably beyond 1.1.20.
What impact does CVE-1999-1273 have on system security?
CVE-1999-1273 allows unauthorized access to resources by bypassing configured access control, compromising the integrity and confidentiality of web data.
Which versions are affected by CVE-1999-1273?
CVE-1999-1273 specifically affects Squid Web Proxy Cache version 1.1.20.
What type of attack does CVE-1999-1273 facilitate?
CVE-1999-1273 facilitates URL manipulation attacks that allow users to circumvent security measures implemented through access control lists.