CVE-2005-0174
15Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackepss 51%
probabilidad de explotación
51%top 1% de las CVE
explotación observada
noninguna fuente lo reporta
Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache or conduct certain attacks via headers that do not follow the HTTP specification, including (1) multiple Content-Length headers, (2) carriage return (CR) characters that are not part of a CRLF pair, and (3) header names containing whitespace characters.
Productos afectados
n/a · n/aReferencias
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000931http://fedoranews.org/updates/FEDORA--.shtmlhttp://marc.info/?l=bugtraq&m=110780531820947&w=2https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10656http://www3.br.squid-cache.org/Advisories/SQUID-2005_4.txthttp://www.kb.cert.org/vuls/id/768702http://www.mandriva.com/security/advisories?name=MDKSA-2005:034http://www.novell.com/linux/security/advisories/2005_06_squid.htmlhttp://www.redhat.com/archives/fedora-announce-list/2005-May/msg00025.htmlhttp://www.redhat.com/support/errata/RHSA-2005-060.htmlhttp://www.redhat.com/support/errata/RHSA-2005-061.htmlhttp://www.securityfocus.com/bid/12412