Home page logo

oss-sec logo oss-sec mailing list archives

Re: CVE-request(?): squid: buffer overflow in Gopher reply parser
From: Josh Bressers <bressers () redhat com>
Date: Tue, 30 Aug 2011 15:44:24 -0400 (EDT)

This needs a 2011 CVE id.

Use CVE-2011-3205.



----- Original Message -----

squid 3.x seems to have re-introduced a security issue found by Ben
Hawkes of
the Google Security Team in 2005,

2011: http://www.squid-cache.org/Advisories/SQUID-2011_3.txt
2005: http://www.squid-cache.org/Advisories/SQUID-2005_1.txt

Will there be a new CVE required? Not quite sure how such "special"
cases are
handled usually.


Matthias Weckbecker, Junior Software Engineer, SUSE Security Team
SUSE LINUX Products GmbH, Maxfeldstr. 5, D-90409 Nuernberg, Germany
Tel: +49-911-74053-0; http://suse.com/
SUSE LINUX Products GmbH, GF: Jeff Hawn, HRB 16746 (AG Nuernberg)

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]