CVE-2004-0189
squid - ACL bypass
EPSS 2.5%
Description
The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL ("%00") character, which causes Squid to use only a portion of the requested URL when comparing it against the access control lists.
How to fix CVE-2004-0189
To remediate CVE-2004-0189, upgrade the affected package to a fixed version below.
- Debian/squid—upgrade to 2.5.5-1 or later
- Debian/squid—upgrade to 2.4.6-2woody2 or later
Is CVE-2004-0189 being exploited?
Low — EPSS is 2.5%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 2.5.5-1
- from 0, < 2.4.6-2woody2