[<prev] [next>] [thread-next>] [month] [year] [list]
Date: Mon, 20 Jul 2009 11:33:29 -0600
From: Vincent Danen <vdanen@...hat.com>
To: oss-security@...ts.openwall.com
Subject: squid DoS in external auth header parser
I noticed this on Debian's bts [1] and also on upstream's bugzilla [2]
but no CVE has been assigned (not sure if one has been requested or not,
but I've not seen a request come through here).
By the initial looks of things, it seems to be a fairly low severity
issue and may not be easy to duplicate/trigger. The reporter didn't really
provide much in the way of a reproducer or relevant configs (and the
reference to zope auths makes me not even want to touch it).
Has anyone taken a look at this or has a CVE been requested for it?
Upstream has done nothing with this despite it being reported two weeks
ago.
[1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=534982
[2] http://www.squid-cache.org/bugs/show_bug.cgi?id=2704
--
Vincent Danen / Red Hat Security Response Team
Please check out the
Open Source Software Security Wiki, which is counterpart to this
mailing list.
Hosted by DataForce ISP -
Powered by Openwall GNU/*/Linux