oss-sec mailing list archives
squid DoS in external auth header parser
From: Vincent Danen <vdanen () redhat com>
Date: Mon, 20 Jul 2009 11:33:29 -0600
I noticed this on Debian's bts [1] and also on upstream's bugzilla [2] but no CVE has been assigned (not sure if one has been requested or not, but I've not seen a request come through here). By the initial looks of things, it seems to be a fairly low severity issue and may not be easy to duplicate/trigger. The reporter didn't really provide much in the way of a reproducer or relevant configs (and the reference to zope auths makes me not even want to touch it). Has anyone taken a look at this or has a CVE been requested for it? Upstream has done nothing with this despite it being reported two weeks ago. [1] http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=534982 [2] http://www.squid-cache.org/bugs/show_bug.cgi?id=2704 --Vincent Danen / Red Hat Security Response Team
Current thread:
- squid DoS in external auth header parser Vincent Danen (Jul 20)
- Re: squid DoS in external auth header parser security curmudgeon (Aug 03)
- Re: squid DoS in external auth header parser Nico Golde (Aug 04)
- Re: squid DoS in external auth header parser Vincent Danen (Aug 04)
- Re: squid DoS in external auth header parser Nico Golde (Aug 04)
- Re: squid DoS in external auth header parser Vincent Danen (Aug 04)
- Re: squid DoS in external auth header parser Steven M. Christey (Aug 18)
