CVE-2005-0241
EPSS 69.7%
描述
The httpProcessReplyHeader function in http.c for Squid 2.5-STABLE7 and earlier does not properly set the debug context when it is handling "oversized" HTTP reply headers, which might allow remote attackers to poison the cache or bypass access controls based on header size.
如何修補 CVE-2005-0241
要修補 CVE-2005-0241,請將受影響套件升級到下列已修補版本。
- Debian/squid—升級至 2.5.7-7 或更新版本
CVE-2005-0241 正在被利用嗎?
可能 — EPSS 為 69.7%,屬於高被利用機率區間,建議優先修補。
受影響套件(1)
- from 0, < 2.5.7-7