ID

VAR-200107-0032


CVE

CVE-2001-1030


TITLE

Squid HTTP Accelerator mode illegal activity vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-200107-116

DESCRIPTION

Squid before 2.3STABLE5 in HTTP accelerator mode does not enable access control lists (ACLs) when the httpd_accel_host and http_accel_with_proxy off settings are used, which allows attackers to bypass the ACLs and conduct unauthorized activities such as port scanning

Trust: 0.99

sources: NVD: CVE-2001-1030 // VULHUB: VHN-3835

AFFECTED PRODUCTS

vendor:trustixmodel:secure linuxscope:eqversion:1.2

Trust: 1.6

vendor:immunixmodel:immunixscope:eqversion:7.0

Trust: 1.0

vendor:immunixmodel:immunixscope:eqversion:7.0_beta

Trust: 1.0

vendor:squidmodel:web proxyscope:eqversion:2.3stable4

Trust: 1.0

vendor:mandrakesoftmodel:mandrake linuxscope:eqversion:7.1

Trust: 1.0

vendor:mandrakesoftmodel:mandrake single network firewallscope:eqversion:7.2

Trust: 1.0

vendor:immunixmodel:immunixscope:eqversion:6.2

Trust: 1.0

vendor:calderamodel:openlinux serverscope:eqversion:3.1

Trust: 1.0

vendor:mandrakesoftmodel:mandrake linuxscope:eqversion:7.2

Trust: 1.0

vendor:trustixmodel:secure linuxscope:eqversion:1.1

Trust: 1.0

vendor:redhatmodel:linuxscope:eqversion:7.0

Trust: 1.0

vendor:trustixmodel:secure linuxscope:eqversion:1.01

Trust: 1.0

vendor:mandrakesoftmodel:mandrake linux corporate serverscope:eqversion:1.0.1

Trust: 1.0

vendor:squidmodel:web proxyscope:eqversion:2.3stable3

Trust: 1.0

vendor:mandrakesoftmodel:mandrake linuxscope:eqversion:8.0

Trust: 1.0

sources: CNNVD: CNNVD-200107-116 // NVD: CVE-2001-1030

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2001-1030
value: HIGH

Trust: 1.0

CNNVD: CNNVD-200107-116
value: HIGH

Trust: 0.6

VULHUB: VHN-3835
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2001-1030
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-3835
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-3835 // CNNVD: CNNVD-200107-116 // NVD: CVE-2001-1030

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2001-1030

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200107-116

TYPE

unknown

Trust: 0.6

sources: CNNVD: CNNVD-200107-116

EXTERNAL IDS

db:NVDid:CVE-2001-1030

Trust: 1.7

db:CNNVDid:CNNVD-200107-116

Trust: 0.7

db:REDHATid:RHSA-2001:097

Trust: 0.6

db:CALDERAid:CSSA-2001-029.0

Trust: 0.6

db:MANDRAKEid:MDKSA-2001:066

Trust: 0.6

db:BUGTRAQid:20010718 SQUID HTTPD ACCELERATION ACL BUG ENABLES PORTSCANNING

Trust: 0.6

db:BUGTRAQid:20010719 TSLSA-2001-0013 - SQUID

Trust: 0.6

db:XFid:6862

Trust: 0.6

db:IMMUNIXid:IMNX-2001-70-031-01

Trust: 0.6

db:VULHUBid:VHN-3835

Trust: 0.1

sources: VULHUB: VHN-3835 // CNNVD: CNNVD-200107-116 // NVD: CVE-2001-1030

REFERENCES

url:http://www.securityfocus.com/archive/1/197727

Trust: 1.7

url:http://archives.neohapsis.com/archives/bugtraq/2001-07/0362.html

Trust: 1.7

url:http://www.calderasystems.com/support/security/advisories/cssa-2001-029.0.txt

Trust: 1.7

url:http://download.immunix.org/immunixos/7.0/updates/imnx-2001-70-031-01

Trust: 1.7

url:http://www.linux-mandrake.com/en/security/2001/mdksa-2001-066.php3

Trust: 1.7

url:http://www.redhat.com/support/errata/rhsa-2001-097.html

Trust: 1.7

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/6862

Trust: 1.1

url:http://xforce.iss.net/static/6862.php

Trust: 0.6

sources: VULHUB: VHN-3835 // CNNVD: CNNVD-200107-116 // NVD: CVE-2001-1030

SOURCES

db:VULHUBid:VHN-3835
db:CNNVDid:CNNVD-200107-116
db:NVDid:CVE-2001-1030

LAST UPDATE DATE

2024-08-14T15:15:16.463000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-3835date:2017-10-10T00:00:00
db:CNNVDid:CNNVD-200107-116date:2006-09-15T00:00:00
db:NVDid:CVE-2001-1030date:2017-10-10T01:29:58.407

SOURCES RELEASE DATE

db:VULHUBid:VHN-3835date:2001-07-18T00:00:00
db:CNNVDid:CNNVD-200107-116date:2001-07-18T00:00:00
db:NVDid:CVE-2001-1030date:2001-07-18T04:00:00