CVE-2004-0832

Publication date 3 November 2004

Last updated 24 July 2024


Ubuntu priority

The (1) ntlm_fetch_string and (2) ntlm_get_string functions in Squid 2.5.6 and earlier, with NTLM authentication enabled, allow remote attackers to cause a denial of service (application crash) via an NTLMSSP packet that causes a negative value to be passed to memcpy.

Status

Package Ubuntu Release Status
squid 7.04 feisty
Fixed 2.6.5-4ubuntu2
6.10 edgy
Fixed 2.6.1-3ubuntu1.3
6.06 LTS dapper
Fixed 2.5.12-4ubuntu2.2

References

Related Ubuntu Security Notices (USN)

    • USN-19-1
    • squid vulnerabilities
    • 7 November 2004

Other references