7.5
CVSSv2

CVE-2002-0916

Published: 04/10/2002 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Format string vulnerability in the allowuser code for the Stellar-X msntauth authentication module, as distributed in Squid 2.4.STABLE6 and previous versions, allows remote malicious users to execute arbitrary code via format strings in the user name, which are not properly handled in a syslog call.

Vulnerable Product Search on Vulmon Subscribe to Product

stellar-x software msntauth