CVE-2005-0173
EPSS 1.7%squid - several
Published: 5/2/2005Modified: 4/28/2026
Description
squid_ldap_auth in Squid 2.5 and earlier allows remote authenticated users to bypass username-based Access Control Lists (ACLs) via a username with a space at the beginning or end, which is ignored by the LDAP server.
Affected packages (2)
- Debian/squidfrom 0, < 2.5.7-4
- Debian/squidfrom 0, < 2.4.6-2woody6