← All CVEs

CVE-2004-0918

medium · 5

The asn_parse_header function (asn1.c) in the SNMP module for Squid Web Proxy Cache before 2.4.STABLE7 allows remote attackers to cause a denial of service (server restart) via certain SNMP packets with negative length fields that trigger a memory allocation error.

5
CVSS
16.0%
EPSS (exploit prob.)
97th
EPSS percentile
2005-01-27
Published

AV:N/AC:L/Au:N/C:N/I:N/A:P

Weaknesses

CWE-399

Affected products

VendorProductAffected versions
openpkgopenpkg2.1
openpkgopenpkg2.2
openpkgopenpkgcurrent
squidsquid2.0_patch2
squidsquid2.1_patch2
squidsquid2.3_.stable4
squidsquid2.3_.stable5
squidsquid2.4
squidsquid2.4_.stable2
squidsquid2.4_.stable6
squidsquid2.4_.stable7
squidsquid2.5_.stable1
squidsquid2.5_.stable3
squidsquid2.5_.stable4
squidsquid2.5_.stable5
squidsquid2.5_.stable6
squidsquid3.0_pre1
squidsquid3.0_pre2
squidsquid3.0_pre3
gentoolinuxall versions
redhatfedora_corecore_2.0
trustixsecure_linux1.5
trustixsecure_linux2.0
trustixsecure_linux2.1
ubuntuubuntu_linux4.1
ubuntuubuntu_linux4.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2004-0918