CVE-2004-0189
EPSS 2.5%squid - ACL bypass
Published: 3/15/2004Modified: 4/28/2026
Description
The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL ("%00") character, which causes Squid to use only a portion of the requested URL when comparing it against the access control lists.
Affected packages (2)
- Debian/squidfrom 0, < 2.5.5-1
- Debian/squidfrom 0, < 2.4.6-2woody2