Description
Squid 2.4 STABLE3 and earlier allows remote attackers to cause a denial of service (core dump) and possibly execute arbitrary code with an ftp:// URL with a larger number of special characters, which exceed the buffer when Squid URL-escapes the characters.
Exploits (1)
References (14)
Scores
EPSS
0.0556
EPSS Percentile
90.3%
Details
Status
published
Products (5)
redhat/linux
6.2 (3 CPE variants)
redhat/linux
7.0 (2 CPE variants)
redhat/linux
7.1 (3 CPE variants)
redhat/linux
7.2 (2 CPE variants)
squid/squid
< 2.4_stable_3
Published
Mar 08, 2002
Tracked Since
Feb 18, 2026