Lucene search

K
cve[email protected]CVE-2001-1030
HistoryJun 25, 2002 - 4:00 a.m.

CVE-2001-1030

2002-06-2504:00:00
web.nvd.nist.gov
29
cve-2001-1030
squid
http accelerator
access control lists
acl
unauthorized activity

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6.5 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

61.0%

Squid before 2.3STABLE5 in HTTP accelerator mode does not enable access control lists (ACLs) when the httpd_accel_host and http_accel_with_proxy off settings are used, which allows attackers to bypass the ACLs and conduct unauthorized activities such as port scanning.

Affected configurations

NVD
Node
calderaopenlinux_serverMatch3.1
OR
immuniximmunixMatch6.2
OR
immuniximmunixMatch7.0
OR
immuniximmunixMatch7.0_beta
OR
mandrakesoftmandrake_single_network_firewallMatch7.2
OR
squidsquid_web_proxyMatch2.3stable3
OR
squidsquid_web_proxyMatch2.3stable4
Node
mandrakesoftmandrake_linuxMatch7.1
OR
mandrakesoftmandrake_linuxMatch7.2
OR
mandrakesoftmandrake_linuxMatch8.0
OR
mandrakesoftmandrake_linux_corporate_serverMatch1.0.1
OR
redhatlinuxMatch7.0
OR
trustixsecure_linuxMatch1.1
OR
trustixsecure_linuxMatch1.01
OR
trustixsecure_linuxMatch1.2

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6.5 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

61.0%

Related for CVE-2001-1030