CVE-2001-1030
published 2001-07-18CVE-2001-1030: Squid before 2.3STABLE5 in HTTP accelerator mode does not enable access control lists (ACLs) when the httpd_accel_host and http_accel_with_proxy off settings…
PriorityP425high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
1.96%
78.1th percentile
Squid before 2.3STABLE5 in HTTP accelerator mode does not enable access control lists (ACLs) when the httpd_accel_host and http_accel_with_proxy off settings are used, which allows attackers to bypass the ACLs and conduct unauthorized activities such as port scanning.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| caldera | openlinux_server | — | — |
| immunix | immunix | — | — |
| immunix | immunix | — | — |
| immunix | immunix | — | — |
| mandrakesoft | mandrake_linux | — | — |
| mandrakesoft | mandrake_linux | — | — |
| mandrakesoft | mandrake_linux | — | — |
| mandrakesoft | mandrake_linux_corporate_server | — | — |
| mandrakesoft | mandrake_single_network_firewall | — | — |
| redhat | linux | — | — |
| squid | squid_web_proxy | — | — |
| squid | squid_web_proxy | — | — |
| trustix | secure_linux | — | — |
| trustix | secure_linux | — | — |
| trustix | secure_linux | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g8hh-whpr-gfp2: Squid before 2
ghsa_unreviewed·2022-04-30
CVE-2001-1030 [HIGH] GHSA-g8hh-whpr-gfp2: Squid before 2
Squid before 2.3STABLE5 in HTTP accelerator mode does not enable access control lists (ACLs) when the httpd_accel_host and http_accel_with_proxy off settings are used, which allows attackers to bypass the ACLs and conduct unauthorized activities such as port scanning.
Red Hat
security flaw
vendor_redhat·2001-07-18·CVSS 7.5
CVE-2001-1030 [HIGH] security flaw
security flaw
Squid before 2.3STABLE5 in HTTP accelerator mode does not enable access control lists (ACLs) when the httpd_accel_host and http_accel_with_proxy off settings are used, which allows attackers to bypass the ACLs and conduct unauthorized activities such as port scanning.
No detection rules found.
No public exploits indexed.
http://archives.neohapsis.com/archives/bugtraq/2001-07/0362.htmlhttp://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-031-01http://www.calderasystems.com/support/security/advisories/CSSA-2001-029.0.txthttp://www.linux-mandrake.com/en/security/2001/MDKSA-2001-066.php3http://www.redhat.com/support/errata/RHSA-2001-097.htmlhttp://www.securityfocus.com/archive/1/197727https://exchange.xforce.ibmcloud.com/vulnerabilities/6862http://archives.neohapsis.com/archives/bugtraq/2001-07/0362.htmlhttp://download.immunix.org/ImmunixOS/7.0/updates/IMNX-2001-70-031-01http://www.calderasystems.com/support/security/advisories/CSSA-2001-029.0.txthttp://www.linux-mandrake.com/en/security/2001/MDKSA-2001-066.php3http://www.redhat.com/support/errata/RHSA-2001-097.htmlhttp://www.securityfocus.com/archive/1/197727https://exchange.xforce.ibmcloud.com/vulnerabilities/6862
2001-07-18
Published