CVE-2005-0194
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
02/05/2005
Last modified:
03/04/2025
Description
Squid 2.5, when processing the configuration file, parses empty Access Control Lists (ACLs), including proxy_auth ACLs without defined auth schemes, in a way that effectively removes arguments, which could allow remote attackers to bypass intended ACLs if the administrator ignores the parser warnings.
Impact
Base Score 2.0
10.00
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:squid:squid:2.0.patch1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:squid:squid:2.0.patch2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:squid:squid:2.0.pre1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:squid:squid:2.0.release:*:*:*:*:*:*:* | ||
| cpe:2.3:a:squid:squid:2.1.patch1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:squid:squid:2.1.patch2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:squid:squid:2.1.pre1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:squid:squid:2.1.pre3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:squid:squid:2.1.pre4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:squid:squid:2.1.release:*:*:*:*:*:*:* | ||
| cpe:2.3:a:squid:squid:2.2.devel3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:squid:squid:2.2.devel4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:squid:squid:2.2.pre1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:squid:squid:2.2.pre2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:squid:squid:2.2.stable1:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000923
- http://fedoranews.org/updates/FEDORA--.shtml
- http://marc.info/?l=bugtraq&m=110901183320453&w=2
- http://www.debian.org/security/2005/dsa-667
- http://www.kb.cert.org/vuls/id/260421
- http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-empty_acls
- http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-empty_acls.patch
- http://www.squid-cache.org/bugs/show_bug.cgi?id=1166
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000923
- http://fedoranews.org/updates/FEDORA--.shtml
- http://marc.info/?l=bugtraq&m=110901183320453&w=2
- http://www.debian.org/security/2005/dsa-667
- http://www.kb.cert.org/vuls/id/260421
- http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-empty_acls
- http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-empty_acls.patch
- http://www.squid-cache.org/bugs/show_bug.cgi?id=1166



