CVE-2002-0713
EPSS 1.3%
Description
Buffer overflows in Squid before 2.4.STABLE6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code (1) via the MSNT auth helper (msnt_auth) when using denyusers or allowusers files, (2) via the gopher client, or (3) via the FTP server directory listing parser when HTML output is generated.
How to fix CVE-2002-0713
To remediate CVE-2002-0713, upgrade the affected package to a fixed version below.
- Debian/squid—upgrade to 2.4.6-2 or later
Is CVE-2002-0713 being exploited?
Low — EPSS is 1.3%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 2.4.6-2