First published: Fri Jul 26 2002(Updated: )
Format string vulnerability in the logging() function in C-Note Squid LDAP authentication module (squid_auth_LDAP) 2.0.2 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code by triggering log messages.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
C-Note Squid auth LDAP | =1.0.1 | |
C-Note Squid auth LDAP | =1.0.2_beta | |
C-Note Squid auth LDAP | =1.2_b2 | |
C-Note Squid auth LDAP | =2.0 | |
padl software nss ldap | =build_180 | |
padl software nss ldap | =build_181 | |
padl software nss ldap | =build_183 | |
padl software nss ldap | =build_184 | |
padl software nss ldap | =build_185 | |
padl software nss ldap | =build_185.1 | |
padl software nss ldap | =build_185.2 | |
padl software nss ldap | =build_185.3 | |
padl software nss ldap | =build_186 | |
padl software nss ldap | =build_187 | |
padl software nss ldap | =build_188 | |
padl software nss ldap | =build_189 | |
PADL PAM LDAP | =build_143 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0735 is considered a high severity vulnerability due to the potential for denial of service and arbitrary code execution.
To fix CVE-2002-0735, update to a patched version of the C-Note Squid LDAP authentication module that resolves the format string vulnerability.
CVE-2002-0735 affects C-Note Squid LDAP authentication module versions 2.0.2 and earlier, as well as specific builds of nss_ldap and pam_ldap.
Yes, CVE-2002-0735 can be exploited remotely by attackers to trigger the format string vulnerability.
The impacts of CVE-2002-0735 include service disruption due to denial of service and the risk of arbitrary code execution.