Description
The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL ("%00") character, which causes Squid to use only a portion of the requested URL when comparing it against the access control lists.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2004-0189 | The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL ("%00") character, which causes Squid to use only a portion of the requested URL when comparing it against the access control lists. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-08T00:10:03.868Z
Reserved: 2004-03-03T00:00:00.000Z
Link: CVE-2004-0189
No data.
Status : Modified
Published: 2004-03-15T05:00:00.000
Modified: 2026-04-16T00:27:16.627
Link: CVE-2004-0189
OpenCVE Enrichment
No data.
Weaknesses
EUVD