PT-2002-1736 · Squid · Squid+1
Published
2002-07-26
·
Updated
2016-10-18
·
CVE-2002-0714
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Squid versions prior to 2.4.STABLE6
Description
The issue concerns the FTP proxy functionality, which fails to compare the IP addresses of control and data connections with the FTP server. This allows remote attackers to bypass firewall rules or spoof FTP server responses.
Recommendations
For versions prior to 2.4.STABLE6, update to version 2.4.STABLE6 or later to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Squid
Squid Cache