CVE Vulnerabilities

CVE-2004-0918

Published: Jan 27, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The asn_parse_header function (asn1.c) in the SNMP module for Squid Web Proxy Cache before 2.4.STABLE7 allows remote attackers to cause a denial of service (server restart) via certain SNMP packets with negative length fields that trigger a memory allocation error.

Affected Software

NameVendorStart VersionEnd Version
OpenpkgOpenpkg2.1 (including)2.1 (including)
OpenpkgOpenpkg2.2 (including)2.2 (including)
OpenpkgOpenpkgcurrent (including)current (including)
SquidSquid2.0_patch2 (including)2.0_patch2 (including)
SquidSquid2.1_patch2 (including)2.1_patch2 (including)
SquidSquid2.3_.stable4 (including)2.3_.stable4 (including)
SquidSquid2.3_.stable5 (including)2.3_.stable5 (including)
SquidSquid2.4 (including)2.4 (including)
SquidSquid2.4_.stable2 (including)2.4_.stable2 (including)
SquidSquid2.4_.stable6 (including)2.4_.stable6 (including)
SquidSquid2.4_.stable7 (including)2.4_.stable7 (including)
SquidSquid2.5_.stable1 (including)2.5_.stable1 (including)
SquidSquid2.5_.stable3 (including)2.5_.stable3 (including)
SquidSquid2.5_.stable4 (including)2.5_.stable4 (including)
SquidSquid2.5_.stable5 (including)2.5_.stable5 (including)
SquidSquid2.5_.stable6 (including)2.5_.stable6 (including)
SquidSquid3.0_pre1 (including)3.0_pre1 (including)
SquidSquid3.0_pre2 (including)3.0_pre2 (including)
SquidSquid3.0_pre3 (including)3.0_pre3 (including)
Red Hat Enterprise Linux 3RedHatsquid-7:2.5.STABLE3-6.3E.2*
SquidUbuntudapper*
SquidUbuntudevel*
SquidUbuntuedgy*
SquidUbuntufeisty*

References