5
CVSSv2

CVE-2004-2654

Published: 31/12/2004 Updated: 05/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The clientAbortBody function in client_side.c in Squid Web Proxy Cache prior to 2.6 STABLE6 allows remote malicious users to cause a denial of service (segmentation fault) via unspecified vectors that trigger a null dereference. NOTE: in a followup advisory, a researcher claimed that the issue was a buffer overflow that was not fixed in STABLE6. However, the vendor's bug report clearly shows that the researcher later retracted this claim, because the tested product was actually STABLE5.

Vulnerable Product Search on Vulmon Subscribe to Product

squid squid 2.5_stable5