First published: Tue Jul 23 2002(Updated: )
Buffer overflows in Squid before 2.4.STABLE6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code (1) via the MSNT auth helper (msnt_auth) when using denyusers or allowusers files, (2) via the gopher client, or (3) via the FTP server directory listing parser when HTML output is generated.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Squid Web Proxy Cache | <=2.4.stable6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0713 has a high severity due to its potential to cause denial of service and execute arbitrary code.
To fix CVE-2002-0713, update to Squid version 2.4.STABLE6 or later.
CVE-2002-0713 impacts buffer overflow vulnerabilities in Squid before version 2.4.STABLE6.
Systems using Squid versions earlier than 2.4.STABLE6 are affected by CVE-2002-0713.
CVE-2002-0713 can facilitate remote denial of service attacks and potentially allow for arbitrary code execution.