Security Advisory

CVE-2005-0194

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2005-02-06 05:00:00
Last updated 2024-08-07 21:05:24
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

Squid 2.5, when processing the configuration file, parses empty Access Control Lists (ACLs), including proxy_auth ACLs without defined auth schemes, in a way that effectively removes arguments, which could allow remote attackers to bypass intended ACLs if the administrator ignores the parser warnings.