CVE-2004-2479: Medium severity National Science Foundation Squid Web Proxy Cache vulnerability
Squid Web Proxy Cache 2.5 might allow remote attackers to obtain sensitive information via URLs containing invalid hostnames that cause DNS operations to fail, which results in references to previously used error messages.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-2479?
CVE-2004-2479 is classified as a moderate severity vulnerability that can lead to information disclosure.
How do I fix CVE-2004-2479?
To fix CVE-2004-2479, you should upgrade to a patched version of Squid Web Proxy Cache that addresses this vulnerability.
What are the potential impacts of CVE-2004-2479?
CVE-2004-2479 allows remote attackers to obtain sensitive information through DNS failures that expose former error messages.
Which versions of Squid Web Proxy Cache are affected by CVE-2004-2479?
CVE-2004-2479 affects multiple versions of Squid Web Proxy Cache, including 2.5 stable 1 to 7.
Is CVE-2004-2479 still a relevant concern for current systems?
CVE-2004-2479 may still pose a risk for legacy systems running outdated versions of Squid Web Proxy Cache.