PT-2002-1156 · Squid · Squid+1
Published
2002-03-08
·
Updated
2016-10-18
·
CVE-2002-0067
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Squid versions 2.4 STABLE3 and earlier
Description
The issue is related to the improper disabling of HTCP, which could allow remote attackers to bypass intended access restrictions, even when "htcp port 0" is specified in squid.conf.
Recommendations
For Squid versions 2.4 STABLE3 and earlier, consider disabling the HTCP service as a temporary workaround until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Squid
Squid Cache