Lucene search

K
cve[email protected]CVE-2005-0173
HistoryMay 02, 2005 - 4:00 a.m.

CVE-2005-0173

2005-05-0204:00:00
web.nvd.nist.gov
42
cve-2005-0173
squid_ldap_auth
acl bypass
ldap
remote authentication

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

5.9 Medium

AI Score

Confidence

Low

0.011 Low

EPSS

Percentile

84.4%

squid_ldap_auth in Squid 2.5 and earlier allows remote authenticated users to bypass username-based Access Control Lists (ACLs) via a username with a space at the beginning or end, which is ignored by the LDAP server.

Affected configurations

NVD
Node
squidsquidMatch2.0.patch1
OR
squidsquidMatch2.0.patch2
OR
squidsquidMatch2.0.pre1
OR
squidsquidMatch2.0.release
OR
squidsquidMatch2.1.patch1
OR
squidsquidMatch2.1.patch2
OR
squidsquidMatch2.1.pre1
OR
squidsquidMatch2.1.pre3
OR
squidsquidMatch2.1.pre4
OR
squidsquidMatch2.1.release
OR
squidsquidMatch2.2.devel3
OR
squidsquidMatch2.2.devel4
OR
squidsquidMatch2.2.pre1
OR
squidsquidMatch2.2.pre2
OR
squidsquidMatch2.2.stable1
OR
squidsquidMatch2.2.stable2
OR
squidsquidMatch2.2.stable3
OR
squidsquidMatch2.2.stable4
OR
squidsquidMatch2.2.stable5
OR
squidsquidMatch2.3.devel2
OR
squidsquidMatch2.3.devel3
OR
squidsquidMatch2.3.stable1
OR
squidsquidMatch2.3.stable2
OR
squidsquidMatch2.3.stable3
OR
squidsquidMatch2.3.stable4
OR
squidsquidMatch2.3.stable5
OR
squidsquidMatch2.4.stable1
OR
squidsquidMatch2.4.stable2
OR
squidsquidMatch2.4.stable3
OR
squidsquidMatch2.4.stable4
OR
squidsquidMatch2.4.stable6
OR
squidsquidMatch2.4.stable7
OR
squidsquidMatch2.5.stable1
OR
squidsquidMatch2.5.stable2
OR
squidsquidMatch2.5.stable3
OR
squidsquidMatch2.5.stable4
OR
squidsquidMatch2.5.stable5
OR
squidsquidMatch2.5.stable6

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

5.9 Medium

AI Score

Confidence

Low

0.011 Low

EPSS

Percentile

84.4%