← Vulnerability feed

Vulnerability record · CVE-2005-0241 · published 2 May 2005

CVE-2005-0241: Squid httpProcessReplyHeader mishandles oversized HTTP reply headers

Squid · Squid

Squid 2.5-STABLE7 and earlier fails to properly set the debug context in httpProcessReplyHeader when handling oversized HTTP reply headers. This can let a remote attacker poison the cache or bypass access controls that rely on header size. The record is old and thin, with no CWE mapping beyond 'Other' and no affected-version detail beyond the stated release.

5.0 CVSS 2.0 Medium EPSS 70% · top 0.7%
5.0CVSS 2.0 base score
70%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
26References
16 Jun 2026Last modified by NVD

Description

The httpProcessReplyHeader function in http.c for Squid 2.5-STABLE7 and earlier does not properly set the debug context when it is handling "oversized" HTTP reply headers, which might allow remote attackers to poison the cache or bypass access controls based on header size.

AV:N/AC:L/Au:N/C:N/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

medium priorityCVSS 2.0 rates it MEDIUM with integrity-only impact, but the high EPSS and cache-poisoning potential warrant attention on any still-running Squid 2.5-STABLE7 or earlier.

What it is

Squid 2.5-STABLE7 and earlier fails to properly set the debug context in httpProcessReplyHeader when handling oversized HTTP reply headers. This can let a remote attacker poison the cache or bypass access controls that rely on header size. The record is old and thin, with no CWE mapping beyond 'Other' and no affected-version detail beyond the stated release.

Impact

An attacker may be able to inject or alter cached content and evade header-size-based access controls. The CVSS vector shows integrity impact only, with no confidentiality or availability impact.

Attack surface

Reachable over the network via HTTP traffic processed by the Squid proxy; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV and no ransomware associations are recorded; EPSS is high at 0.69661 (99.3rd percentile), but references are patch and advisory links only, with no public exploit tag.

What to do

  • Upgrade Squid past 2.5-STABLE7 to a fixed release; the vendor patch is referenced at squid-cache.org.
  • Apply the vendor or distribution patches (Red Hat RHSA-2005-060/061, Novell, Conectiva) if upgrading is not immediately possible.
  • Restrict who can send HTTP requests through the proxy to trusted clients where feasible.
  • Review cache and access-control rules that depend on header size, since those checks may be bypassable.

Detection

  • Inspect Squid cache.log and access.log for oversized HTTP reply headers or abnormal header sizes.
  • Monitor for unexpected cache content changes or cache poisoning indicators on the proxy.
  • Alert on access-control decisions that appear inconsistent with configured header-size limits.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000931 Patch
http://fedoranews.org/updates/FEDORA--.shtml
http://secunia.com/advisories/14091
http://www.kb.cert.org/vuls/id/823350 PatchThird Party AdvisoryUS Government Resource
http://www.novell.com/linux/security/advisories/2005_06_squid.html PatchVendor Advisory
http://www.redhat.com/support/errata/RHSA-2005-060.html PatchVendor Advisory
http://www.redhat.com/support/errata/RHSA-2005-061.html PatchVendor Advisory
http://www.securityfocus.com/bid/12412
http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-oversize_reply_headers Patch
http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-oversize_reply_headers.patch Patch
http://www.squid-cache.org/bugs/show_bug.cgi?id=1216 Patch
https://exchange.xforce.ibmcloud.com/vulnerabilities/19060
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10998
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000931 Patch
http://fedoranews.org/updates/FEDORA--.shtml
http://secunia.com/advisories/14091
http://www.kb.cert.org/vuls/id/823350 PatchThird Party AdvisoryUS Government Resource
http://www.novell.com/linux/security/advisories/2005_06_squid.html PatchVendor Advisory
http://www.redhat.com/support/errata/RHSA-2005-060.html PatchVendor Advisory
http://www.redhat.com/support/errata/RHSA-2005-061.html PatchVendor Advisory
http://www.securityfocus.com/bid/12412
http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-oversize_reply_headers Patch
http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-oversize_reply_headers.patch Patch
http://www.squid-cache.org/bugs/show_bug.cgi?id=1216 Patch
https://exchange.xforce.ibmcloud.com/vulnerabilities/19060
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10998

Track CVE-2005-0241 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2005-0194Squid vulnerabilitySquid 2.5, when processing the configuration file, parses empty Access Control Lists (ACLs), including proxy_auth ACLs without defined auth schemes, …EPSS 5.1%7.5CVE-2005-1711Clam anti-virus clamav vulnerabilityGibraltar Firewall 2.2 and earlier, when using the ClamAV update to 0.81 for Squid, uses a defunct ClamAV method to scan memory for viruses, which do…EPSS 1.0%7.5CVE-2005-0173Squid vulnerabilitysquid_ldap_auth in Squid 2.5 and earlier allows remote authenticated users to bypass username-based Access Control Lists (ACLs) via a username with a…EPSS 32%7.5CVE-2005-1345Squid vulnerabilitySquid 2.5.STABLE9 and earlier does not trigger a fatal error when it identifies missing or invalid ACLs in the http_access configuration, which could…EPSS 1.7%7.5CVE-2004-0189Squid vulnerabilityThe "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL ("%00") charac…EPSS 14%7.5CVE-2002-0713Squid vulnerabilityBuffer overflows in Squid before 2.4.STABLE6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code (1) via …EPSS 5.5%7.5CVE-2002-0714Squid vulnerabilityFTP proxy in Squid before 2.4.STABLE6 does not compare the IP addresses of control and data connections with the FTP server, which allows remote atta…EPSS 2.7%7.5CVE-2002-0163Squid vulnerabilityHeap-based buffer overflow in Squid before 2.4 STABLE4, and Squid 2.5 and 2.6 until March 12, 2002 distributions, allows remote attackers to cause a …EPSS 15%

Source: NIST National Vulnerability Database (record CVE-2005-0241), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.