Vulnerabilities > CVE-2002-0163 - Unspecified vulnerability in Squid
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Heap-based buffer overflow in Squid before 2.4 STABLE4, and Squid 2.5 and 2.6 until March 12, 2002 distributions, allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via compressed DNS responses.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | Squid 2.4.1 Remote Buffer Overflow Exploit. CVE-2002-0163. Remote exploit for linux platform |
id | EDB-ID:347 |
last seen | 2016-01-31 |
modified | 2002-05-14 |
published | 2002-05-14 |
reporter | Teso |
source | https://www.exploit-db.com/download/347/ |
title | Squid 2.4.1 - Remote Buffer Overflow Exploit |
Nessus
NASL family | Mandriva Local Security Checks |
NASL id | MANDRAKE_MDKSA-2002-027.NASL |
description | A security issue has recently been found and fixed in the Squid-2.X releases up to and including 2.4.STABLE4. Error and boundary conditions were not checked when handling compressed DNS answer messages in the internal DNS code (lib/rfc1035.c). A malicous DNS server could craft a DNS reply that causes Squid to exit with a SIGSEGV. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 13934 |
published | 2004-07-31 |
reporter | This script is Copyright (C) 2004-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/13934 |
title | Mandrake Linux Security Advisory : squid (MDKSA-2002:027) |
code |
|
Redhat
advisories |
|
References
- ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-017.1.txt
- ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-017.1.txt
- ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-02:19.squid.asc
- ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-02:19.squid.asc
- http://marc.info/?l=bugtraq&m=101716495023226&w=2
- http://marc.info/?l=bugtraq&m=101716495023226&w=2
- http://rhn.redhat.com/errata/RHSA-2002-051.html
- http://rhn.redhat.com/errata/RHSA-2002-051.html
- http://www.iss.net/security_center/static/8628.php
- http://www.iss.net/security_center/static/8628.php
- http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-027.php
- http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-027.php
- http://www.securityfocus.com/bid/4363
- http://www.securityfocus.com/bid/4363
- http://www.squid-cache.org/Advisories/SQUID-2002_2.txt
- http://www.squid-cache.org/Advisories/SQUID-2002_2.txt