Vulnerability Development mailing list archives

patch for squid error page vulnerability


From: Robert Collins <robert.collins () ITDOMAIN COM AU>
Date: Sun, 29 Oct 2000 12:06:49 +1100

Note: This patch may not be the best way of doing things: the squid dev team
will have to look at that :]

This just address's the issue at hand, and will patch cleanly against the
current squid development HEAD from cvs. To patch an earlier squid you
may/will need to do so by hand.
Also some earlier squid's have a %u macro for the error pages as well as the
%U macro that this patch fixes. If you are patching an older squid check to
see if there is a %u and if so fix in the same way..

html.c goes in the lib directory of the squid souce tree. squiderror.diff
was generated from the root of the sourcetree with "diff -N -u"

Rob



Attachment: html.c
Description:

Attachment: squiderror.diff
Description:


Current thread: