Submitted by KeesCook on Fri, 2005-09-30 12:03
Referenced CVEs:
CAN-2005-2917
Description:
===========================================================
Ubuntu Security Notice USN-192-1 September 30, 2005
squid vulnerability
CAN-2005-2917
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 4.10 (Warty Warthog)
Ubuntu 5.04 (Hoary Hedgehog)
The following packages are affected:
squid
The problem can be corrected by upgrading the affected package to
version 2.5.5-6ubuntu0.11 (for Ubuntu 4.10), or 2.5.8-3ubuntu1.4 (for
Ubuntu 5.04). In general, a standard system upgrade is sufficient to
effect the necessary changes.
Details follow:
Mike Diggins discovered a remote Denial of Service vulnerability in
Squid. Sending specially crafted NTML authentication requests to Squid
caused the server to crash.


