First published: Thu Oct 21 2004(Updated: )
The asn_parse_header function (asn1.c) in the SNMP module for Squid Web Proxy Cache before 2.4.STABLE7 allows remote attackers to cause a denial of service (server restart) via certain SNMP packets with negative length fields that trigger a memory allocation error.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Squid Web Proxy Cache | =2.5_.stable3 | |
Squid Web Proxy Cache | =2.1_patch2 | |
Squid Web Proxy Cache | =2.4_.stable7 | |
Openpetra | =2.1 | |
Squid Web Proxy Cache | =2.0_patch2 | |
Squid Web Proxy Cache | =2.4_.stable2 | |
Squid Web Proxy Cache | =2.3_.stable4 | |
Squid Web Proxy Cache | =2.3_.stable5 | |
Squid Web Proxy Cache | =2.5_.stable5 | |
Openpetra | =current | |
Squid Web Proxy Cache | =3.0_pre1 | |
Squid Web Proxy Cache | =2.5_.stable6 | |
Openpetra | =2.2 | |
Squid Web Proxy Cache | =2.4_.stable6 | |
Squid Web Proxy Cache | =2.5_.stable1 | |
Squid Web Proxy Cache | =2.4 | |
Squid Web Proxy Cache | =2.5_.stable4 | |
Squid Web Proxy Cache | =3.0_pre3 | |
Squid Web Proxy Cache | =3.0_pre2 | |
Red Hat Fedora Core | =core_2.0 | |
Trustix Secure Linux | =2.0 | |
Ubuntu | =4.1 | |
Trustix Secure Linux | =1.5 | |
Trustix Secure Linux | =2.1 | |
Ubuntu | =4.1 | |
Gentoo Linux |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0918 is classified as a denial of service vulnerability that can lead to server restarts.
To fix CVE-2004-0918, upgrade to Squid Web Proxy Cache version 2.4.STABLE7 or later.
CVE-2004-0918 affects various versions of Squid Web Proxy Cache and Openpkg software.
CVE-2004-0918 is caused by processing certain SNMP packets with negative length fields, resulting in a memory allocation error.
Yes, CVE-2004-0918 can be exploited remotely by sending specially crafted SNMP packets.