CVE-2002-0713
published 2002-07-26CVE-2002-0713: Buffer overflows in Squid before 2.4.STABLE6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code (1) via the MSNT…
PriorityP427high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
5.54%
92.0th percentile
Buffer overflows in Squid before 2.4.STABLE6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code (1) via the MSNT auth helper (msnt_auth) when using denyusers or allowusers files, (2) via the gopher client, or (3) via the FTP server directory listing parser when HTML output is generated.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | squid | < squid 2.4.6-2 (bookworm) | squid 2.4.6-2 (bookworm) |
| squid | squid | <= 2.4.stable6 | — |
| squid | squid | >= 0 < 2.4.6-2 | 2.4.6-2 |
| squid | squid | >= 0 < 2.4.6-2 | 2.4.6-2 |
| squid | squid | >= 0 < 2.4.6-2 | 2.4.6-2 |
| squid | squid | >= 0 < 2.4.6-2 | 2.4.6-2 |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8hcw-fv7v-vpjj: Buffer overflows in Squid before 2
ghsa_unreviewed·2022-05-03
CVE-2002-0713 [HIGH] GHSA-8hcw-fv7v-vpjj: Buffer overflows in Squid before 2
Buffer overflows in Squid before 2.4.STABLE6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code (1) via the MSNT auth helper (msnt_auth) when using denyusers or allowusers files, (2) via the gopher client, or (3) via the FTP server directory listing parser when HTML output is generated.
OSV
CVE-2002-0713: Buffer overflows in Squid before 2
osv·2002-07-26·CVSS 7.5
CVE-2002-0713 [HIGH] CVE-2002-0713: Buffer overflows in Squid before 2
Buffer overflows in Squid before 2.4.STABLE6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code (1) via the MSNT auth helper (msnt_auth) when using denyusers or allowusers files, (2) via the gopher client, or (3) via the FTP server directory listing parser when HTML output is generated.
Red Hat
security flaw
vendor_redhat·2002-07-03·CVSS 7.5
CVE-2002-0713 [HIGH] security flaw
security flaw
Buffer overflows in Squid before 2.4.STABLE6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code (1) via the MSNT auth helper (msnt_auth) when using denyusers or allowusers files, (2) via the gopher client, or (3) via the FTP server directory listing parser when HTML output is generated.
Debian
CVE-2002-0713: squid - Buffer overflows in Squid before 2.4.STABLE6 allow remote attackers to cause a d...
vendor_debian·2002·CVSS 7.5
CVE-2002-0713 [HIGH] CVE-2002-0713: squid - Buffer overflows in Squid before 2.4.STABLE6 allow remote attackers to cause a d...
Buffer overflows in Squid before 2.4.STABLE6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code (1) via the MSNT auth helper (msnt_auth) when using denyusers or allowusers files, (2) via the gopher client, or (3) via the FTP server directory listing parser when HTML output is generated.
Scope: local
bookworm: resolved (fixed in 2.4.6-2)
bullseye: resolved (fixed in 2.4.6-2)
forky: resolved (fixed in 2.4.6-2)
sid: resolved (fixed in 2.4.6-2)
trixie: resolved (fixed in 2.4.6-2)
No detection rules found.
No public exploits indexed.
ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-046.0.txthttp://marc.info/?l=bugtraq&m=102674543407606&w=2http://rhn.redhat.com/errata/RHSA-2002-051.htmlhttp://rhn.redhat.com/errata/RHSA-2002-130.htmlhttp://www.iss.net/security_center/static/9480.phphttp://www.iss.net/security_center/static/9481.phphttp://www.iss.net/security_center/static/9482.phphttp://www.linux-mandrake.com/en/security/2002/MDKSA-2002-044.phphttp://www.securityfocus.com/bid/5155http://www.securityfocus.com/bid/5156http://www.securityfocus.com/bid/5157http://www.squid-cache.org/Advisories/SQUID-2002_3.txthttp://www.squid-cache.org/Versions/v2/2.4/bugs/ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-046.0.txthttp://marc.info/?l=bugtraq&m=102674543407606&w=2http://rhn.redhat.com/errata/RHSA-2002-051.htmlhttp://rhn.redhat.com/errata/RHSA-2002-130.htmlhttp://www.iss.net/security_center/static/9480.phphttp://www.iss.net/security_center/static/9481.phphttp://www.iss.net/security_center/static/9482.phphttp://www.linux-mandrake.com/en/security/2002/MDKSA-2002-044.phphttp://www.securityfocus.com/bid/5155http://www.securityfocus.com/bid/5156http://www.securityfocus.com/bid/5157http://www.squid-cache.org/Advisories/SQUID-2002_3.txthttp://www.squid-cache.org/Versions/v2/2.4/bugs/
2002-07-26
Published