Vulnerabilities > CVE-2002-0916 - Unspecified vulnerability in Stellar-X Software Msntauth
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Format string vulnerability in the allowuser code for the Stellar-X msntauth authentication module, as distributed in Squid 2.4.STABLE6 and earlier, allows remote attackers to execute arbitrary code via format strings in the user name, which are not properly handled in a syslog call.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
References
- http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0087.html
- http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0087.html
- http://online.securityfocus.com/archive/1/275347
- http://online.securityfocus.com/archive/1/275347
- http://www.iss.net/security_center/static/9248.php
- http://www.iss.net/security_center/static/9248.php
- http://www.securityfocus.com/bid/4929
- http://www.securityfocus.com/bid/4929
- http://www.squid-cache.org/Versions/v2/2.4/diff-2.4.STABLE6-2.4.STABLE7.gz
- http://www.squid-cache.org/Versions/v2/2.4/diff-2.4.STABLE6-2.4.STABLE7.gz