Back

CVE-2002-0735

Format string vulnerability in the logging() function in C-Note Squid LDAP authentication module (squid_auth_LDAP) 2.0.2 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code by triggering log messages.

Published: Aug 12, 2002 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (17)

Vendor Product Version
c-note squid_auth_ldap 1.0.1
c-note squid_auth_ldap 1.0.2_beta
c-note squid_auth_ldap 1.2_b2
c-note squid_auth_ldap 2.0
padl_software nss_ldap build_180
padl_software nss_ldap build_181
padl_software nss_ldap build_183
padl_software nss_ldap build_184
padl_software nss_ldap build_185
padl_software nss_ldap build_185.1
padl_software nss_ldap build_185.2
padl_software nss_ldap build_185.3
padl_software nss_ldap build_186
padl_software nss_ldap build_187
padl_software nss_ldap build_188
padl_software nss_ldap build_189
padl_software pam_ldap build_143

GitHub Security Advisory GHSA-g6h3-4wm6-7hpq

Format string vulnerability in the logging() function in C-Note Squid LDAP authentication module ...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 2.94%

Top 14% most likely to be exploited

Threat Score 30.9 / 100

Data Sources

NVD EPSS GitHub