The (1) ntlm_fetch_string and (2) ntlm_get_string functions in Squid 2.5.6 and previous versions, with NTLM authentication enabled, allow remote malicious users to cause a denial of service (application crash) via an NTLMSSP packet that causes a negative value to be passed to memcpy.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
squid squid |