HIGH · 7.5

CVE-2001-1030

Squid before 2.3STABLE5 in HTTP accelerator mode does not enable access control lists (ACLs) when the httpd_accel_host and http_accel_with_proxy off settings are used, which allows attackers to bypass...

Vulnerability Description

Squid before 2.3STABLE5 in HTTP accelerator mode does not enable access control lists (ACLs) when the httpd_accel_host and http_accel_with_proxy off settings are used, which allows attackers to bypass the ACLs and conduct unauthorized activities such as port scanning.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
CalderaOpenlinux Server3.1
ImmunixImmunix6.2
MandrakesoftMandrake Single Network Firewall7.2
SquidSquid Web Proxy2.3stable3
MandrakesoftMandrake Linux7.1
MandrakesoftMandrake Linux Corporate Server1.0.1
RedhatLinux7.0
TrustixSecure Linux1.1

References

FAQ

What is CVE-2001-1030?

CVE-2001-1030 is a vulnerability with a CVSS score of 7.5 (HIGH). Squid before 2.3STABLE5 in HTTP accelerator mode does not enable access control lists (ACLs) when the httpd_accel_host and http_accel_with_proxy off settings are used, which allows attackers to bypass...

How severe is CVE-2001-1030?

CVE-2001-1030 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2001-1030?

Check the references section above for vendor advisories and patch information. Affected products include: Caldera Openlinux Server, Immunix Immunix, Mandrakesoft Mandrake Single Network Firewall, Squid Squid Web Proxy, Mandrakesoft Mandrake Linux.