oss-sec mailing list archives

Re: CVE request: Squid <2.7.6, 3.0.13, 3.1.0.5 DoS


From: Josh Bressers <bressers () redhat com>
Date: Sun, 8 Feb 2009 20:39:56 -0500 (EST)


----- "Steven M. Christey" <coley () linus mitre org> wrote:

I do subscribe to oss-security so see these emails.  Still working on the
best process to be able to respond more quickly.

The SQUID advisory doesn't state what kind of DoS it is, and it's not
clear from the patches either.  Is it a crash, hang, resource consumption,
etc.?  Not essential from a CVE perspective but probanly convenient to
Squid users.

I have more information in the Red Hat bug:
https://bugzilla.redhat.com/show_bug.cgi?id=484246

A remote user can trigger an assert() call, so it's a crash basically.

-- 
    JB


Current thread: