VulnerabilityModified
CVE-2002-0715
Vulnerability in Squid before 2.4.STABLE6 related to proxy authentication credentials may allow remote web sites to obtain the user's proxy login and password.
MEDIUM 5.0EPSS 2.30%
Does this matter?
Lower severity and a low EPSS score (2.30%). Track it; it rarely justifies an emergency change on its own.
Description
Vulnerability in Squid before 2.4.STABLE6 related to proxy authentication credentials may allow remote web sites to obtain the user's proxy login and password.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.30% probability · 82th percentile
- CISA KEV
- Not listed
- Affected
- squid/squid
- Source
- cve@mitre.org
References
- ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-046.0.txt
- http://marc.info/?l=bugtraq&m=102674543407606&w=2
- http://rhn.redhat.com/errata/RHSA-2002-051.html
- http://rhn.redhat.com/errata/RHSA-2002-130.htmlPatch, Vendor Advisory
- http://www.iss.net/security_center/static/9478.php
- http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-044.phpPatch
- http://www.securityfocus.com/bid/5154
- http://www.squid-cache.org/Advisories/SQUID-2002_3.txtPatch, Vendor Advisory
- http://www.squid-cache.org/Versions/v2/2.4/bugs/Patch
- ftp://ftp.caldera.com/pub/security/OpenLinux/CSSA-2002-046.0.txt
- http://marc.info/?l=bugtraq&m=102674543407606&w=2
- http://rhn.redhat.com/errata/RHSA-2002-051.html
- http://rhn.redhat.com/errata/RHSA-2002-130.htmlPatch, Vendor Advisory
- http://www.iss.net/security_center/static/9478.php
- http://www.linux-mandrake.com/en/security/2002/MDKSA-2002-044.phpPatch
- http://www.securityfocus.com/bid/5154
- http://www.squid-cache.org/Advisories/SQUID-2002_3.txtPatch, Vendor Advisory
- http://www.squid-cache.org/Versions/v2/2.4/bugs/Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.