CVE-2005-2796
EPSS 15.1%
Description
The sslConnectTimeout function in ssl.c for Squid 2.5.STABLE10 and earlier allows remote attackers to cause a denial of service (segmentation fault) via certain crafted requests.
How to fix CVE-2005-2796
To remediate CVE-2005-2796, upgrade the affected package to a fixed version below.
- Debian/squid—upgrade to 2.5.10-5 or later
Is CVE-2005-2796 being exploited?
Moderate — EPSS is 15.1%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 2.5.10-5