Lucene search

K
freebsdFreeBSD6F955451-BA54-11D8-B88C-000D610A3B12
HistoryMay 20, 2004 - 12:00 a.m.

Buffer overflow in Squid NTLM authentication helper

2004-05-2000:00:00
vuxml.freebsd.org
22

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.963

Percentile

99.6%

Remote exploitation of a buffer overflow vulnerability in
the NTLM authentication helper routine of the Squid Web
Proxy Cache could allow a remote attacker to execute
arbitrary code. A remote attacker can compromise a target
system if the Squid Proxy is configured to use the NTLM
authentication helper. The attacker can send an overly long
password to overflow the buffer and execute arbitrary
code.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchsquid< 2.5.5_9UNKNOWN

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.963

Percentile

99.6%