PT-2004-1894 · Squid · Squid+1
Published
2004-09-28
·
Updated
2017-10-11
·
CVE-2004-0832
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions:
Squid versions 2.5.6 and earlier
Description:
The issue concerns the
ntlm fetch string and ntlm get string functions in Squid when NTLM authentication is enabled. It allows remote attackers to cause a denial of service, resulting in an application crash. This is achieved by sending an NTLMSSP packet that causes a negative value to be passed to memcpy.Recommendations:
For Squid versions 2.5.6 and earlier, consider disabling NTLM authentication until a patch is available.
As a temporary workaround, restrict access to the
ntlm fetch string and ntlm get string functions to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Squid
Squid Cache