5
CVSSv2

CVE-2004-0832

Published: 03/11/2004 Updated: 11/10/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The (1) ntlm_fetch_string and (2) ntlm_get_string functions in Squid 2.5.6 and previous versions, with NTLM authentication enabled, allow remote malicious users to cause a denial of service (application crash) via an NTLMSSP packet that causes a negative value to be passed to memcpy.

Vulnerable Product Search on Vulmon Subscribe to Product

squid squid

Vendor Advisories

Synopsis squid security update Type/Severity Security Advisory: Moderate Topic An updated squid package that fixes a security vulnerability in the NTLMauthentication helper is now available Description Squid is a full-featured Web proxy cacheAn out of bounds memory read bug was found with ...
Recently, two Denial of Service vulnerabilities have been discovered in squid, a WWW proxy cache Insufficient input validation in the NTLM authentication handler allowed a remote attacker to crash the service by sending a specially crafted NTLMSSP packet Likewise, due to an insufficient validation of ASN1 headers, a remote attacker could restart ...