CVE
- Id
- 5103
- CVE No.
- CVE-2002-0713
- Status
- Candidate
- Description
- Buffer overflows in Squid before 2.4.STABLE6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code (1) via the MSNT auth helper (msnt_auth) when using denyusers or allowusers files, (2) via the gopher client, or (3) via the FTP server directory listing parser when HTML output is generated.
- Phase
- Modified (20050601)
- Votes
- ACCEPT(4) Armstrong, Baker, Cole, Cox | MODIFY(1) Frech | NOOP(3) Christey, Foat, Wall
- Comments
- Christey> VULNWATCH:20020603 [VulnWatch] [DER #11] - Remotey exploitable fmt string bug in squid | URL:http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0087.html | BUGTRAQ:20020604 [DER #11] - Remotey exploitable fmt string bug in squid | URL:http://online.securityfocus.com/archive/1/275347 | | Note that this report is for the "msntauth" module, which | itself is out-of-date, but there is obviously a codebase relationship | with what"s included in the Squid distribution. | Frech> XF:squid-msnt-helper-bo(9482) | Christey> CALDERA:CSSA-2002-046.0 | URL:ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-046.0.txt | REDHAT:RHSA-2002:051 | URL:http://rhn.redhat.com/errata/RHSA-2002-051.html | Christey> CALDERA:CSSA-2003-SCO.9