CVE-2005-0241: Medium severity Squid Squid vulnerability
Published Feb 8, 2005
·Updated
The httpProcessReplyHeader function in http.c for Squid 2.5-STABLE7 and earlier does not properly set the debug context when it is handling "oversized" HTTP reply headers, which might allow remote attackers to poison the cache or bypass access controls based on header size.
Affected Software
7 affected components
Squid Squid=2.5.stable1
Squid Squid=2.5.stable2
Squid Squid=2.5.stable3
Squid Squid=2.5.stable4
Squid Squid=2.5.stable5
Squid Squid=2.5.stable6
Squid Squid=2.5.stable7
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Feb 8, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-0241?
CVE-2005-0241 has a medium severity rating due to potential cache poisoning and access control bypass risks.
2
How do I fix CVE-2005-0241?
To fix CVE-2005-0241, upgrade to a version of Squid newer than 2.5-STABLE7.
3
What versions of Squid are affected by CVE-2005-0241?
CVE-2005-0241 affects Squid versions 2.5-STABLE1 through 2.5-STABLE7.
4
What are the potential impacts of CVE-2005-0241?
The impacts of CVE-2005-0241 include cache poisoning and the ability for attackers to bypass access controls.
5
Is CVE-2005-0241 likely to be exploited?
Yes, CVE-2005-0241 can be exploited by remote attackers if systems are running affected versions of Squid.