Submitted by KeesCook on Sat, 2004-11-06 12:00
Referenced CVEs:
CAN-2004-0832, CAN-2004-0918
Description:
===========================================================
Ubuntu Security Notice USN-19-1 November 06, 2004
squid vulnerabilities
CAN-2004-0832, CAN-2004-0918
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 4.10 (Warty Warthog)
The following packages are affected:
squid
The problem can be corrected by upgrading the affected package to
version 2.5.5-6ubuntu0.2. In general, a standard system upgrade is
sufficient to effect the necessary changes.
Details follow:
Recently, two Denial of Service vulnerabilities have been discovered
in squid, a WWW proxy cache. Insufficient input validation in the NTLM
authentication handler allowed a remote attacker to crash the service
by sending a specially crafted NTLMSSP packet. Likewise, due to an
insufficient validation of ASN.1 headers, a remote attacker could
restart the server (causing all open connections to be dropped) by
sending certain SNMP packets with negative length fields.


