CVE-2004-2654
Last modified
CVE-2004-2654 is a vulnerability of currently unknown severity. The clientAbortBody function in client_side.c in Squid Web Proxy Cache before 2.6 STABLE6 allows remote attackers to cause a denial of service (segmentation fault) via unspecified vectors that trigger a null dereference. NOTE: in a followup advisory, a researcher claimed that the issue was a buffer overflow that was not fixed in STABLE6. EPSS estimates a 1.99% chance of exploitation in the next 30 days.
Description
The clientAbortBody function in client_side.c in Squid Web Proxy Cache before 2.6 STABLE6 allows remote attackers to cause a denial of service (segmentation fault) via unspecified vectors that trigger a null dereference. NOTE: in a followup advisory, a researcher claimed that the issue was a buffer overflow that was not fixed in STABLE6. However, the vendor's bug report clearly shows that the researcher later retracted this claim, because the tested product was actually STABLE5.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Squid | Squid | 2.5_stable5 |
References
- http://secunia.com/advisories/12508Vendor Advisory
- http://secunia.com/advisories/12754Patch, Vendor Advisory
- http://secunia.com/advisories/12508Vendor Advisory
- http://secunia.com/advisories/12754Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-2654?
How severe is CVE-2004-2654?
How do I fix CVE-2004-2654?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2004
- CVE-2004-2648FreezeX 1.00.100.0666 allows local users with administrator …
- CVE-2004-2649Eudora 6.1.0.6 allows remote attackers to obfuscate URLs dis…
- CVE-2004-2650Spooler in Apache Foundation James 2.2.0 allows local users …
- CVE-2004-2651Multiple cross-site scripting (XSS) vulnerabilities in YaCy …
- CVE-2004-2652The DecodeTCPOptions function in decode.c in Snort before 2.…
- CVE-2004-2653Unspecified vulnerability in PD9 Software MegaBBS 2.0 and 2.…
- CVE-2004-2655rdesktop 1.3.1 with xscreensaver 4.14, and possibly other ve…
- CVE-2004-2656Multiple cross-site scripting (XSS) vulnerabilities in Slash…
- CVE-2004-2657Mozilla Firefox 1.5.0.1, and possibly other versions, preser…
- CVE-2004-2658resmgr in SUSE CORE 9 does not properly identify terminal na…
- CVE-2004-2659Opera offers an Open button to verify that a user wishes to …
- CVE-2004-2660Memory leak in direct-io.c in Linux kernel 2.6.x before 2.6.…
Are you affected by CVE-2004-2654?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
