PT-2001-2177 · Squid · Squid
Publicado
2001-07-18
·
Atualizado
2017-10-10
·
CVE-2001-1030
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Squid versions prior to 2.3STABLE5
Description
The issue allows attackers to bypass access control lists (ACLs) and conduct unauthorized activities, such as port scanning, when specific settings are used in HTTP accelerator mode.
Recommendations
For versions prior to 2.3STABLE5, update to version 2.3STABLE5 or later to enable access control lists (ACLs) when the httpd accel host and http accel with proxy off settings are used.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Squid