CVE-2005-0174
EPSS 50.8%
描述
Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache or conduct certain attacks via headers that do not follow the HTTP specification, including (1) multiple Content-Length headers, (2) carriage return (CR) characters that are not part of a CRLF pair, and (3) header names containing whitespace characters.
如何修補 CVE-2005-0174
要修補 CVE-2005-0174,請將受影響套件升級到下列已修補版本。
- Debian/squid—升級至 2.5.7-6 或更新版本
CVE-2005-0174 正在被利用嗎?
可能 — EPSS 為 50.8%,屬於高被利用機率區間,建議優先修補。
受影響套件(1)
- from 0, < 2.5.7-6