CVE-2004-2654

Source
https://cve.org/CVERecord?id=CVE-2004-2654
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2004-2654.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2004-2654
Downstream
Published
2004-12-31T05:00:00Z
Modified
2026-04-10T03:36:45.428881Z
Summary
[none]
Details

The clientAbortBody function in client_side.c in Squid Web Proxy Cache before 2.6 STABLE6 allows remote attackers to cause a denial of service (segmentation fault) via unspecified vectors that trigger a null dereference. NOTE: in a followup advisory, a researcher claimed that the issue was a buffer overflow that was not fixed in STABLE6. However, the vendor's bug report clearly shows that the researcher later retracted this claim, because the tested product was actually STABLE5.

References

Affected packages