CSSA-2002-SCO.7Vendor advisory
http://archives.neohapsis.com/archives/linux/caldera/2002-q1/0014.html CVE-2002-0068
Squid 2.0-4 - Cache FTP Proxy URL Buffer Overflow
Record summary
CVE-2002-0068 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
Squid 2.4 STABLE3 and earlier allows remote attackers to cause a denial of service (core dump) and possibly execute arbitrary code with an ftp:// URL with a larger number of special characters, which exceed the buffer when Squid URL-escapes the characters.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBSquid 2.0-4 - Cache FTP Proxy URL Buffer OverflowExploitDB exploitby gunzipNot analyzed1 file
References
Showing 12 of 14CLA-2002:464Vendor advisory
http://distro.conectiva.com.br/atualizacoes?id=a&anuncio=000464 20020221 Squid HTTP Proxy Security Update Advisory 2002:1mailing list
http://marc.info/?l=bugtraq&m=101431040422095&w=2 20020222 Squid buffer overflowmailing list
http://marc.info/?l=bugtraq&m=101440163111826&w=2 20020222 TSLSA-2002-0031 - squidmailing list
http://marc.info/?l=bugtraq&m=101443252627021&w=2 CSSA-2002-010.0Vendor advisory
http://www.caldera.com/support/security/advisories/CSSA-2002-010.0.txt squid-ftpbuildtitleurl-bo(8258)vdb entry
http://www.iss.net/security_center/static/8258.php MDKSA-2002:016Vendor advisory
http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-016.php SuSE-SA:2002:008Vendor advisory
http://www.novell.com/linux/security/advisories/2002_008_squid_txt.html 5378vdb entry
http://www.osvdb.org/5378 RHSA-2002:029Vendor advisory
http://www.redhat.com/support/errata/RHSA-2002-029.html 4148vdb entry
http://www.securityfocus.com/bid/4148