7.5

CVE-2002-0068

Exploit

Squid 2.4 STABLE3 and earlier allows remote attackers to cause a denial of service (core dump) and possibly execute arbitrary code with an ftp:// URL with a larger number of special characters, which exceed the buffer when Squid URL-escapes the characters.

Data is provided by the National Vulnerability Database (NVD)
SquidSquid Version <= 2.4_stable_3
RedhatLinux Version6.2 Editionalpha
RedhatLinux Version6.2 Editioni386
RedhatLinux Version6.2 Editionsparc
RedhatLinux Version7.0 Editionalpha
RedhatLinux Version7.0 Editioni386
RedhatLinux Version7.1 Editionalpha
RedhatLinux Version7.1 Editioni386
RedhatLinux Version7.1 Editionia64
RedhatLinux Version7.2 Editioni386
RedhatLinux Version7.2 Editionia64
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 5.56% 0.893
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P