CVE-2001-1030: High severity Caldera Openlinux Server vulnerability
Squid before 2.3STABLE5 in HTTP accelerator mode does not enable access control lists (ACLs) when the httpdaccelhost and httpaccelwithproxy off settings are used, which allows attackers to bypass the ACLs and conduct unauthorized activities such as port scanning.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2001-1030?
CVE-2001-1030 is considered a high severity vulnerability due to its potential to allow unauthorized access and activities.
How do I fix CVE-2001-1030?
To fix CVE-2001-1030, upgrade to a version of Squid that is 2.3STABLE5 or newer, which includes the necessary ACL enforcement.
What systems are affected by CVE-2001-1030?
CVE-2001-1030 affects versions of Squid before 2.3STABLE5 and several specific operating systems like Red Hat Linux, Immunix, and Mandrake Linux.
What kind of attacks can CVE-2001-1030 allow?
CVE-2001-1030 can allow attackers to bypass access control lists, enabling unauthorized actions such as port scanning.
Is there a workaround for CVE-2001-1030 if I cannot upgrade?
If upgrading is not feasible, configuring more restrictive access control settings and monitoring network traffic may help mitigate the risks associated with CVE-2001-1030.