Vulnerability CVE-2004-2479


Published: 2004-12-31   Modified: 2012-02-12

Description:
Squid Web Proxy Cache 2.5 might allow remote attackers to obtain sensitive information via URLs containing invalid hostnames that cause DNS operations to fail, which results in references to previously used error messages.

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
National science foundation -> Squid web proxy cache 

 References:
http://fedoranews.org/updates/FEDORA--.shtml
http://securitytracker.com/id?1012466
http://www.redhat.com/support/errata/RHSA-2005-766.html
http://www.securityfocus.com/bid/11865
http://www.squid-cache.org/bugs/show_bug.cgi?id=1143
https://exchange.xforce.ibmcloud.com/vulnerabilities/18406
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9711

Copyright 2024, cxsecurity.com

 

Back to Top