CVE-2005-0194
published 2005-05-02CVE-2005-0194: Squid 2.5, when processing the configuration file, parses empty Access Control Lists (ACLs), including proxy_auth ACLs without defined auth schemes, in a way…
PriorityP338critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
5.12%
91.5th percentile
Squid 2.5, when processing the configuration file, parses empty Access Control Lists (ACLs), including proxy_auth ACLs without defined auth schemes, in a way that effectively removes arguments, which could allow remote attackers to bypass intended ACLs if the administrator ignores the parser warnings.
Affected
43 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | squid | < squid 2.5.7-7 (bookworm) | squid 2.5.7-7 (bookworm) |
| squid | squid | — | — |
| squid | squid | — | — |
| squid | squid | — | — |
| squid | squid | — | — |
| squid | squid | — | — |
| squid | squid | — | — |
| squid | squid | — | — |
| squid | squid | — | — |
| squid | squid | — | — |
| squid | squid | — | — |
| squid | squid | — | — |
| squid | squid | — | — |
| squid | squid | — | — |
| squid | squid | — | — |
| squid | squid | — | — |
| squid | squid | — | — |
| squid | squid | — | — |
| squid | squid | — | — |
| squid | squid | — | — |
| squid | squid | — | — |
| squid | squid | — | — |
| squid | squid | — | — |
| squid | squid | — | — |
| squid | squid | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Squid vulnerabilities
vendor_ubuntu·2005-02-21
CVE-2005-0194 Squid vulnerabilities
Title: Squid vulnerabilities
Summary: Squid vulnerabilities
When parsing the configuration file, squid interpreted empty Access
Control Lists (ACLs) without defined authentication schemes in a
non-obvious way. This could allow remote attackers to bypass intended
ACLs. (CAN-2005-0194)
A remote Denial of Service vulnerability was discovered in the domain
name resolution code. A faulty or malicious DNS server could stop the
Squid server immediately by sending a malformed IP address.
(CAN-2005-0446)
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2005-0194: squid - Squid 2.5, when processing the configuration file, parses empty Access Control L...
vendor_debian·2005·CVSS 10.0
CVE-2005-0194 [CRITICAL] CVE-2005-0194: squid - Squid 2.5, when processing the configuration file, parses empty Access Control L...
Squid 2.5, when processing the configuration file, parses empty Access Control Lists (ACLs), including proxy_auth ACLs without defined auth schemes, in a way that effectively removes arguments, which could allow remote attackers to bypass intended ACLs if the administrator ignores the parser warnings.
Scope: local
bookworm: resolved (fixed in 2.5.7-7)
bullseye: resolved (fixed in 2.5.7-7)
forky: resolved (fixed in 2.5.7-7)
sid: resolved (fixed in 2.5.7-7)
trixie: resolved (fixed in 2.5.7-7)
GHSA
GHSA-3vc4-p4vg-f376: Squid 2
ghsa_unreviewed·2022-05-01
CVE-2005-0194 [HIGH] GHSA-3vc4-p4vg-f376: Squid 2
Squid 2.5, when processing the configuration file, parses empty Access Control Lists (ACLs), including proxy_auth ACLs without defined auth schemes, in a way that effectively removes arguments, which could allow remote attackers to bypass intended ACLs if the administrator ignores the parser warnings.
OSV
CVE-2005-0194: Squid 2
osv·2005-05-02·CVSS 10.0
CVE-2005-0194 [CRITICAL] CVE-2005-0194: Squid 2
Squid 2.5, when processing the configuration file, parses empty Access Control Lists (ACLs), including proxy_auth ACLs without defined auth schemes, in a way that effectively removes arguments, which could allow remote attackers to bypass intended ACLs if the administrator ignores the parser warnings.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000923http://fedoranews.org/updates/FEDORA--.shtmlhttp://marc.info/?l=bugtraq&m=110901183320453&w=2http://www.debian.org/security/2005/dsa-667http://www.kb.cert.org/vuls/id/260421http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-empty_aclshttp://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-empty_acls.patchhttp://www.squid-cache.org/bugs/show_bug.cgi?id=1166http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000923http://fedoranews.org/updates/FEDORA--.shtmlhttp://marc.info/?l=bugtraq&m=110901183320453&w=2http://www.debian.org/security/2005/dsa-667http://www.kb.cert.org/vuls/id/260421http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-empty_aclshttp://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-empty_acls.patchhttp://www.squid-cache.org/bugs/show_bug.cgi?id=1166
2005-05-02
Published