CVE-2002-0713Improper Restriction of Operations within the Bounds of a Memory Buffer in Squid

6 documents6 sources
Severity
7.5HIGHNVD
EPSS
1.3%
top 19.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 26
Latest updateMay 3

Description

Buffer overflows in Squid before 2.4.STABLE6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code (1) via the MSNT auth helper (msnt_auth) when using denyusers or allowusers files, (2) via the gopher client, or (3) via the FTP server directory listing parser when HTML output is generated.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages3 packages

debiandebian/squid< squid 2.4.6-2 (bookworm)
Debiansquid/squid< 2.4.6-2+3
NVDsquid/squid2.4.stable6

Patches

🔴Vulnerability Details

2
GHSA
GHSA-8hcw-fv7v-vpjj: Buffer overflows in Squid before 22022-05-03
OSV
CVE-2002-0713: Buffer overflows in Squid before 22002-07-26

📋Vendor Advisories

2
Red Hat
security flaw2002-07-03
Debian
CVE-2002-0713: squid - Buffer overflows in Squid before 2.4.STABLE6 allow remote attackers to cause a d...2002

💬Community

1
Bugzilla
CVE-2002-0713 security flaw2018-08-16