// For flags

CVE-2007-0247

Squid Proxy 2.5/2.6 - FTP URI Remote Denial of Service

Severity Score

7.5
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

squid/src/ftp.c in Squid before 2.6.STABLE7 allows remote FTP servers to cause a denial of service (core dump) via crafted FTP directory listing responses, possibly related to the (1) ftpListingFinish and (2) ftpHtmlifyListEntry functions.

El archivo squid/src/ftp.c en Squid versiones anteriores a 2.6.STABLE7, permite a los servidores FTP remotos causar una denegación de servicio (volcado del núcleo) por medio de respuestas de enumeración de directorio FTP, posiblemente relacionadas con las funciones (1) ftpListingFinish y (2) ftpHtmlifyListEntry.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2007-01-16 CVE Reserved
  • 2007-01-16 CVE Published
  • 2007-01-16 First Exploit
  • 2024-08-07 CVE Updated
  • 2025-04-02 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-399: Resource Management Errors
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Squid
Search vendor "Squid"
Squid
Search vendor "Squid" for product "Squid"
2.6.stable1
Search vendor "Squid" for product "Squid" and version "2.6.stable1"
-
Affected
Squid
Search vendor "Squid"
Squid
Search vendor "Squid" for product "Squid"
2.6.stable2
Search vendor "Squid" for product "Squid" and version "2.6.stable2"
-
Affected
Squid
Search vendor "Squid"
Squid
Search vendor "Squid" for product "Squid"
2.6.stable3
Search vendor "Squid" for product "Squid" and version "2.6.stable3"
-
Affected
Squid
Search vendor "Squid"
Squid
Search vendor "Squid" for product "Squid"
2.6.stable4
Search vendor "Squid" for product "Squid" and version "2.6.stable4"
-
Affected
Squid
Search vendor "Squid"
Squid
Search vendor "Squid" for product "Squid"
2.6.stable5
Search vendor "Squid" for product "Squid" and version "2.6.stable5"
-
Affected
Squid
Search vendor "Squid"
Squid
Search vendor "Squid" for product "Squid"
2.6.stable6
Search vendor "Squid" for product "Squid" and version "2.6.stable6"
-
Affected