CVE-2007-0247 describes a denial-of-service vulnerability in Squid versions prior to 2.6.STABLE7, specifically within the ftp.c component. Remote FTP servers can trigger a core dump by sending specially crafted directory listing responses, impacting the availability of the Squid proxy. With a CVSS score of 5.0 and an AV:N/AC:L/Au:N/C:N/I:N/A:P vector, this vulnerability is easily exploitable over the network without authentication, leading to a complete denial of service. While not on the KEV catalog and with no active exploitation reported, an exploit for this vulnerability is publicly available on ExploitDB, indicating a potential for attack. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.6.stable1CPE matchmatch criteria | cpe:2.3:a:squid:squid:2.6.stable1:*:*:*:*:*:*:* | ||
2.6.stable2CPE matchmatch criteria | cpe:2.3:a:squid:squid:2.6.stable2:*:*:*:*:*:*:* | ||
2.6.stable3CPE matchmatch criteria | cpe:2.3:a:squid:squid:2.6.stable3:*:*:*:*:*:*:* | ||
2.6.stable4CPE matchmatch criteria | cpe:2.3:a:squid:squid:2.6.stable4:*:*:*:*:*:*:* | ||
2.6.stable5CPE matchmatch criteria | cpe:2.3:a:squid:squid:2.6.stable5:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.