First published: Fri Jul 26 2002(Updated: )
FTP proxy in Squid before 2.4.STABLE6 does not compare the IP addresses of control and data connections with the FTP server, which allows remote attackers to bypass firewall rules or spoof FTP server responses.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Squid Web Proxy Cache | <=2.4.stable6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0714 is considered a moderate severity vulnerability due to the potential for remote attackers to exploit it.
To fix CVE-2002-0714, upgrade to Squid version 2.4.STABLE7 or later.
CVE-2002-0714 affects all versions of Squid prior to 2.4.STABLE7.
CVE-2002-0714 allows attackers to bypass firewall rules and spoof FTP server responses.
CVE-2002-0714 operates by failing to compare the IP addresses of control and data connections with the FTP server.