CVE-2005-0173

EPSS 1.7%

squid - several

Published: 5/2/2005Modified: 4/28/2026

Description

squid_ldap_auth in Squid 2.5 and earlier allows remote authenticated users to bypass username-based Access Control Lists (ACLs) via a username with a space at the beginning or end, which is ignored by the LDAP server.

Affected packages (2)

References (1)