Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2007-0247

CWE-3999 documents9 sources
Severity
5.0MEDIUM
EPSS
40.1%
top 2.67%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedJan 16
Latest updateMay 1

Description

squid/src/ftp.c in Squid before 2.6.STABLE7 allows remote FTP servers to cause a denial of service (core dump) via crafted FTP directory listing responses, possibly related to the (1) ftpListingFinish and (2) ftpHtmlifyListEntry functions.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

โ–ถDebiansquid< 2.6.5-4+3
โ–ถNVDsquid/squid6 versions+5

๐Ÿ”ดVulnerability Details

3
GHSA
GHSA-qjvg-797h-7j24: squid/src/ftpโ†—2022-05-01
โ–ถ
OSV
CVE-2007-0247: squid/src/ftpโ†—2007-01-16
โ–ถ
CVEList
CVE-2007-0247: squid/src/ftpโ†—2007-01-16
โ–ถ

๐Ÿ’ฅExploits & PoCs

1
Exploit-DB
Squid Proxy 2.5/2.6 - FTP URI Remote Denial of Serviceโ†—2007-01-16
โ–ถ

๐Ÿ“‹Vendor Advisories

3
Ubuntu
Squid vulnerabilitiesโ†—2007-01-25
โ–ถ
Red Hat
CVE-2007-0247 Squid crashes when receiving certain FTP listingsโ†—2007-01-13
โ–ถ
Debian
CVE-2007-0247: squid - squid/src/ftp.c in Squid before 2.6.STABLE7 allows remote FTP servers to cause a...โ†—2007
โ–ถ

๐Ÿ’ฌCommunity

1
Bugzilla
CVE-2007-0247 Squid crashes when receiving certain FTP listingsโ†—2007-01-16
โ–ถ