First published: Wed Jul 18 2001(Updated: )
Squid before 2.3STABLE5 in HTTP accelerator mode does not enable access control lists (ACLs) when the httpd_accel_host and http_accel_with_proxy off settings are used, which allows attackers to bypass the ACLs and conduct unauthorized activities such as port scanning.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Squid Squid Web Proxy | =2.3stable3 | |
Immunix Immunix | =7.0 | |
Immunix Immunix | =6.2 | |
Immunix Immunix | =7.0_beta | |
Squid Squid Web Proxy | =2.3stable4 | |
Mandrakesoft Mandrake Single Network Firewall | =7.2 | |
Caldera Openlinux Server | =3.1 | |
Mandrakesoft Mandrake Linux | =7.2 | |
Trustix Secure Linux | =1.1 | |
Redhat Linux | =7.0 | |
Trustix Secure Linux | =1.01 | |
Mandrakesoft Mandrake Linux Corporate Server | =1.0.1 | |
Mandrakesoft Mandrake Linux | =7.1 | |
Trustix Secure Linux | =1.2 | |
Mandrakesoft Mandrake Linux | =8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.