The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL ("%00") character, which causes Squid to use only a portion of the requested URL when comparing it against the access control lists.
2004-03-15T05:00:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | squid | squid | 2.0_patch2 | Yes |
Application | squid | squid | 2.1_patch2 | Yes |
Application | squid | squid | 2.3_stable5 | Yes |
Application | squid | squid | 2.4 | Yes |
Application | squid | squid | 2.4_stable7 | Yes |
Application | squid | squid | 2.5_stable3 | Yes |
Application | squid | squid | 2.5_stable4 | Yes |