Vulnerability Name: | CVE-2004-0832 (CCN-17218) | ||||||||||||||||
Assigned: | 2004-08-18 | ||||||||||||||||
Published: | 2004-08-18 | ||||||||||||||||
Updated: | 2017-10-11 | ||||||||||||||||
Summary: | The (1) ntlm_fetch_string and (2) ntlm_get_string functions in Squid 2.5.6 and earlier, with NTLM authentication enabled, allow remote attackers to cause a denial of service (application crash) via an NTLMSSP packet that causes a negative value to be passed to memcpy. | ||||||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
| ||||||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||||||
Vulnerability Consequences: | Denial of Service | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2004-0832 Source: CCN Type: Conectiva Linux Security Announcement CLSA-2004:882 Fixes for squid vulnerabilities Source: FEDORA Type: UNKNOWN FLSA-2006:152809 Source: CCN Type: RHSA-2004-462 squid security update Source: CCN Type: GLSA-200409-04 Squid: Denial of service when using NTLM authentication Source: GENTOO Type: Patch, Vendor Advisory GLSA-200409-04 Source: MANDRAKE Type: UNKNOWN MDKSA-2004:093 Source: BID Type: Patch, Vendor Advisory 11098 Source: CCN Type: BID-11098 Squid Proxy NTLM Authentication Denial Of Service Vulnerability Source: CCN Type: Bugzilla Bug 1045 ntlm_fetch_string wrong "if" statement Source: CONFIRM Type: UNKNOWN http://www.squid-cache.org/bugs/show_bug.cgi?id=1045 Source: TRUSTIX Type: Patch, Vendor Advisory 2004-0047 Source: CCN Type: TLSA-2004-29 DoS vulnerability in squid Source: CCN Type: USN-19-1 squid vulnerabilities Source: CCN Type: Squid Web Proxy Cache Web site Squid Source: CONFIRM Type: UNKNOWN http://www1.uk.squid-cache.org/squid/Versions/v2/2.5/bugs/#squid-2.5.STABLE6-ntlm_fetch_string Source: XF Type: UNKNOWN squid-ntlmssp-dos(17218) Source: XF Type: UNKNOWN squid-ntlmssp-dos(17218) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:10489 Source: SUSE Type: SUSE-SA:2004:032 apache2: remote denial-of-service Source: SUSE Type: SUSE-SA:2004:033 gtk2 gdk-pixbuf: remote code execution Source: SUSE Type: SUSE-SA:2004:034 XFree86-libs xshared: remote command execution | ||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration RedHat 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |