oss-sec mailing list archives
Re: CVE request: Squid <2.7.6, 3.0.13, 3.1.0.5 DoS
From: Josh Bressers <bressers () redhat com>
Date: Sun, 8 Feb 2009 20:39:56 -0500 (EST)
----- "Steven M. Christey" <coley () linus mitre org> wrote:
I do subscribe to oss-security so see these emails. Still working on the best process to be able to respond more quickly. The SQUID advisory doesn't state what kind of DoS it is, and it's not clear from the patches either. Is it a crash, hang, resource consumption, etc.? Not essential from a CVE perspective but probanly convenient to Squid users.
I have more information in the Red Hat bug: https://bugzilla.redhat.com/show_bug.cgi?id=484246 A remote user can trigger an assert() call, so it's a crash basically. -- JB
Current thread:
- CVE request: Squid <2.7.6, 3.0.13, 3.1.0.5 DoS Robert Buchholz (Feb 04)
- Re: CVE request: Squid <2.7.6, 3.0.13, 3.1.0.5 DoS Josh Bressers (Feb 06)
- Re: CVE request: Squid <2.7.6, 3.0.13, 3.1.0.5 DoS Robert Buchholz (Feb 07)
- Re: CVE request: Squid <2.7.6, 3.0.13, 3.1.0.5 DoS Steven M. Christey (Feb 08)
- Re: CVE request: Squid <2.7.6, 3.0.13, 3.1.0.5 DoS Josh Bressers (Feb 08)
- Re: CVE request: Squid <2.7.6, 3.0.13, 3.1.0.5 DoS Robert Buchholz (Feb 07)
- Re: CVE request: Squid <2.7.6, 3.0.13, 3.1.0.5 DoS Josh Bressers (Feb 06)