PT-2001-2177 · Squid · Squid
Published
2001-07-18
·
Updated
2017-10-10
·
CVE-2001-1030
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Squid versions prior to 2.3STABLE5
Description
The issue allows attackers to bypass access control lists (ACLs) and conduct unauthorized activities, such as port scanning, when specific settings are used in HTTP accelerator mode.
Recommendations
For versions prior to 2.3STABLE5, update to version 2.3STABLE5 or later to enable access control lists (ACLs) when the httpd accel host and http accel with proxy off settings are used.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Squid