← Vulnerability feed

Vulnerability record · CVE-2005-2917 · published 30 September 2005

CVE-2005-2917: Squid vulnerability

Squid · Squid

Squid 2.5.STABLE10 and earlier, while performing NTLM authentication, does not properly handle certain request sequences, which allows attackers to cause a denial of service (daemon restart).

5.0 CVSS 2.0 Medium EPSS 3.4% · top 11.6%
5.0CVSS 2.0 base score
3.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
40References
16 Jun 2026Last modified by NVD

Description

Squid 2.5.STABLE10 and earlier, while performing NTLM authentication, does not properly handle certain request sequences, which allows attackers to cause a denial of service (daemon restart).

AV:N/AC:L/Au:N/C:N/I:N/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt
ftp://patches.sgi.com/support/free/security/advisories/20060401-01-U
http://fedoranews.org/updates/FEDORA--.shtml
http://secunia.com/advisories/16992 PatchVendor Advisory
http://secunia.com/advisories/17015
http://secunia.com/advisories/17050
http://secunia.com/advisories/17177
http://secunia.com/advisories/19161
http://secunia.com/advisories/19532
http://securitytracker.com/id?1014920
http://www.debian.org/security/2005/dsa-828 PatchVendor Advisory
http://www.mandriva.com/security/advisories?name=MDKSA-2005:181
http://www.novell.com/linux/security/advisories/2005_27_sr.html
http://www.osvdb.org/19607
http://www.redhat.com/support/errata/RHSA-2006-0045.html
http://www.redhat.com/support/errata/RHSA-2006-0052.html
http://www.securityfocus.com/bid/14977
http://www.ubuntu.com/usn/usn-192-1/
https://exchange.xforce.ibmcloud.com/vulnerabilities/24282
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11580
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt
ftp://patches.sgi.com/support/free/security/advisories/20060401-01-U
http://fedoranews.org/updates/FEDORA--.shtml
http://secunia.com/advisories/16992 PatchVendor Advisory
http://secunia.com/advisories/17015
http://secunia.com/advisories/17050
http://secunia.com/advisories/17177
http://secunia.com/advisories/19161
http://secunia.com/advisories/19532
http://securitytracker.com/id?1014920
http://www.debian.org/security/2005/dsa-828 PatchVendor Advisory
http://www.mandriva.com/security/advisories?name=MDKSA-2005:181
http://www.novell.com/linux/security/advisories/2005_27_sr.html
http://www.osvdb.org/19607
http://www.redhat.com/support/errata/RHSA-2006-0045.html
http://www.redhat.com/support/errata/RHSA-2006-0052.html
http://www.securityfocus.com/bid/14977
http://www.ubuntu.com/usn/usn-192-1/
https://exchange.xforce.ibmcloud.com/vulnerabilities/24282
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11580

Track CVE-2005-2917 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2005-0194Squid vulnerabilitySquid 2.5, when processing the configuration file, parses empty Access Control Lists (ACLs), including proxy_auth ACLs without defined auth schemes, …EPSS 5.1%7.5CVE-2005-1711Clam anti-virus clamav vulnerabilityGibraltar Firewall 2.2 and earlier, when using the ClamAV update to 0.81 for Squid, uses a defunct ClamAV method to scan memory for viruses, which do…EPSS 1.0%7.5CVE-2005-0173Squid vulnerabilitysquid_ldap_auth in Squid 2.5 and earlier allows remote authenticated users to bypass username-based Access Control Lists (ACLs) via a username with a…EPSS 32%7.5CVE-2005-1345Squid vulnerabilitySquid 2.5.STABLE9 and earlier does not trigger a fatal error when it identifies missing or invalid ACLs in the http_access configuration, which could…EPSS 1.7%7.5CVE-2004-0189Squid vulnerabilityThe "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL ("%00") charac…EPSS 14%7.5CVE-2002-0713Squid vulnerabilityBuffer overflows in Squid before 2.4.STABLE6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code (1) via …EPSS 5.5%7.5CVE-2002-0714Squid vulnerabilityFTP proxy in Squid before 2.4.STABLE6 does not compare the IP addresses of control and data connections with the FTP server, which allows remote atta…EPSS 2.7%7.5CVE-2002-0163Squid vulnerabilityHeap-based buffer overflow in Squid before 2.4 STABLE4, and Squid 2.5 and 2.6 until March 12, 2002 distributions, allows remote attackers to cause a …EPSS 15%

Source: NIST National Vulnerability Database (record CVE-2005-2917), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.