First published: Fri Mar 08 2002(Updated: )
Squid 2.4 STABLE3 and earlier allows remote attackers to cause a denial of service (core dump) and possibly execute arbitrary code with an ftp:// URL with a larger number of special characters, which exceed the buffer when Squid URL-escapes the characters.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Squid Web Proxy Cache | <=2.4_stable_3 | |
Red Hat Linux | =7.2 | |
Red Hat Linux | =6.2 | |
Red Hat Linux | =7.1 | |
Red Hat Linux | =7.0 | |
Red Hat Linux | =6.2 | |
Red Hat Linux | =7.1 | |
Red Hat Linux | =7.1 | |
Red Hat Linux | =6.2 | |
Red Hat Linux | =7.0 | |
Red Hat Linux | =7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0068 is a denial-of-service vulnerability that allows remote attackers to potentially crash the server and may lead to arbitrary code execution.
To fix CVE-2002-0068, upgrade to a later version of Squid that does not have this vulnerability.
CVE-2002-0068 affects Squid version 2.4 STABLE3 and earlier.
Yes, CVE-2002-0068 can be exploited remotely using specially crafted FTP URLs.
CVE-2002-0068 facilitates denial-of-service attacks and could allow for remote code execution.