CVE-2002-0916
published 2002-10-04CVE-2002-0916: Format string vulnerability in the allowuser code for the Stellar-X msntauth authentication module, as distributed in Squid 2.4.STABLE6 and earlier, allows…
PriorityP335high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
2.94%
85.7th percentile
Format string vulnerability in the allowuser code for the Stellar-X msntauth authentication module, as distributed in Squid 2.4.STABLE6 and earlier, allows remote attackers to execute arbitrary code via format strings in the user name, which are not properly handled in a syslog call.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | squid | < squid 2.4.7 (bookworm) | squid 2.4.7 (bookworm) |
| squid | squid | >= 0 < 2.4.7 | 2.4.7 |
| squid | squid | >= 0 < 2.4.7 | 2.4.7 |
| squid | squid | >= 0 < 2.4.7 | 2.4.7 |
| squid | squid | >= 0 < 2.4.7 | 2.4.7 |
| stellar-x_software | msntauth | <= 2.0.3 | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5m3q-wwrg-m59p: Format string vulnerability in the allowuser code for the Stellar-X msntauth authentication module, as distributed in Squid 2
ghsa_unreviewed·2022-04-30
CVE-2002-0916 [HIGH] GHSA-5m3q-wwrg-m59p: Format string vulnerability in the allowuser code for the Stellar-X msntauth authentication module, as distributed in Squid 2
Format string vulnerability in the allowuser code for the Stellar-X msntauth authentication module, as distributed in Squid 2.4.STABLE6 and earlier, allows remote attackers to execute arbitrary code via format strings in the user name, which are not properly handled in a syslog call.
OSV
CVE-2002-0916: Format string vulnerability in the allowuser code for the Stellar-X msntauth authentication module, as distributed in Squid 2
osv·2002-10-04·CVSS 7.5
CVE-2002-0916 [HIGH] CVE-2002-0916: Format string vulnerability in the allowuser code for the Stellar-X msntauth authentication module, as distributed in Squid 2
Format string vulnerability in the allowuser code for the Stellar-X msntauth authentication module, as distributed in Squid 2.4.STABLE6 and earlier, allows remote attackers to execute arbitrary code via format strings in the user name, which are not properly handled in a syslog call.
Debian
CVE-2002-0916: squid - Format string vulnerability in the allowuser code for the Stellar-X msntauth aut...
vendor_debian·2002·CVSS 7.5
CVE-2002-0916 [HIGH] CVE-2002-0916: squid - Format string vulnerability in the allowuser code for the Stellar-X msntauth aut...
Format string vulnerability in the allowuser code for the Stellar-X msntauth authentication module, as distributed in Squid 2.4.STABLE6 and earlier, allows remote attackers to execute arbitrary code via format strings in the user name, which are not properly handled in a syslog call.
Scope: local
bookworm: resolved (fixed in 2.4.7)
bullseye: resolved (fixed in 2.4.7)
forky: resolved (fixed in 2.4.7)
sid: resolved (fixed in 2.4.7)
trixie: resolved (fixed in 2.4.7)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0087.htmlhttp://online.securityfocus.com/archive/1/275347http://www.iss.net/security_center/static/9248.phphttp://www.securityfocus.com/bid/4929http://www.squid-cache.org/Versions/v2/2.4/diff-2.4.STABLE6-2.4.STABLE7.gzhttp://archives.neohapsis.com/archives/vulnwatch/2002-q2/0087.htmlhttp://online.securityfocus.com/archive/1/275347http://www.iss.net/security_center/static/9248.phphttp://www.securityfocus.com/bid/4929http://www.squid-cache.org/Versions/v2/2.4/diff-2.4.STABLE6-2.4.STABLE7.gz
2002-10-04
Published