Lucene search

K
cve[email protected]CVE-2002-0735
HistoryAug 12, 2002 - 4:00 a.m.

CVE-2002-0735

2002-08-1204:00:00
web.nvd.nist.gov
23
cve-2002-0735
format string vulnerability
c-note
squid
ldap
authentication
denial of service
remote attackers
arbitrary code

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8 High

AI Score

Confidence

High

0.059 Low

EPSS

Percentile

93.5%

Format string vulnerability in the logging() function in C-Note Squid LDAP authentication module (squid_auth_LDAP) 2.0.2 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code by triggering log messages.

Affected configurations

NVD
Node
c-notesquid_auth_ldapMatch1.0.1
OR
c-notesquid_auth_ldapMatch1.0.2_beta
OR
c-notesquid_auth_ldapMatch1.2_b2
OR
c-notesquid_auth_ldapMatch2.0
OR
padl_softwarenss_ldapMatchbuild_180
OR
padl_softwarenss_ldapMatchbuild_181
OR
padl_softwarenss_ldapMatchbuild_183
OR
padl_softwarenss_ldapMatchbuild_184
OR
padl_softwarenss_ldapMatchbuild_185
OR
padl_softwarenss_ldapMatchbuild_185.1
OR
padl_softwarenss_ldapMatchbuild_185.2
OR
padl_softwarenss_ldapMatchbuild_185.3
OR
padl_softwarenss_ldapMatchbuild_186
OR
padl_softwarenss_ldapMatchbuild_187
OR
padl_softwarenss_ldapMatchbuild_188
OR
padl_softwarenss_ldapMatchbuild_189
OR
padl_softwarepam_ldapMatchbuild_143

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8 High

AI Score

Confidence

High

0.059 Low

EPSS

Percentile

93.5%

Related for CVE-2002-0735