CVE-2005-2917

10 documents8 sources
Severity
5.0MEDIUM
EPSS
51.9%
top 2.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 30
Latest updateMay 3

Description

Squid 2.5.STABLE10 and earlier, while performing NTLM authentication, does not properly handle certain request sequences, which allows attackers to cause a denial of service (daemon restart).

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

Debiansquid< 2.5.10-7+3
NVDsquid/squid2.5.stable10+1

Patches

🔴Vulnerability Details

3
GHSA
GHSA-5hg5-x4p6-wgf5: Squid 22022-05-03
CVEList
CVE-2005-2917: Squid 22005-09-30
OSV
CVE-2005-2917: Squid 22005-09-30

📋Vendor Advisories

3
Ubuntu
Squid vulnerability2005-10-01
Red Hat
security flaw2005-09-15
Debian
CVE-2005-2917: squid - Squid 2.5.STABLE10 and earlier, while performing NTLM authentication, does not p...2005

💬Community

3
Bugzilla
CVE-2005-2917 security flaw2018-08-16
Bugzilla
CVE-2005-2917 Squid malformed NTLM authentication DoS2005-11-23
Bugzilla
CVE-2005-2917 Squid malformed NTLM authentication DoS2005-09-15