CVE-2005-0173
squid - several
EPSS 31.9%
描述
squid_ldap_auth in Squid 2.5 and earlier allows remote authenticated users to bypass username-based Access Control Lists (ACLs) via a username with a space at the beginning or end, which is ignored by the LDAP server.
如何修補 CVE-2005-0173
要修補 CVE-2005-0173,請將受影響套件升級到下列已修補版本。
- Debian/squid—升級至 2.5.7-4 或更新版本
- Debian/squid—升級至 2.4.6-2woody6 或更新版本
CVE-2005-0173 正在被利用嗎?
中等 — EPSS 為 31.9%,可持續追蹤但非最高優先。
受影響套件(2)
- from 0, < 2.5.7-4
- from 0, < 2.4.6-2woody6