CVE-2005-0174: Medium severity Squid Squid vulnerability
Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache or conduct certain attacks via headers that do not follow the HTTP specification, including (1) multiple Content-Length headers, (2) carriage return (CR) characters that are not part of a CRLF pair, and (3) header names containing whitespace characters.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-0174?
CVE-2005-0174 is considered a medium severity vulnerability that allows cache poisoning and may lead to certain attacks.
How do I fix CVE-2005-0174?
To fix CVE-2005-0174, update Squid to a version later than 2.5.STABLE7.
What versions of Squid are affected by CVE-2005-0174?
CVE-2005-0174 affects Squid versions 2.5 up to 2.5.STABLE7.
What types of attacks does CVE-2005-0174 allow?
CVE-2005-0174 allows attackers to poison the cache or conduct attacks through malformed HTTP headers.
Is there a patch available for CVE-2005-0174?
Yes, a patch is available through newer versions of Squid beyond 2.5.STABLE7.