[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Tue, 4 Aug 2009 12:13:29 +0200
From: Nico Golde <oss-security+ml@...lde.de>
To: oss-security@...ts.openwall.com
Subject: Re: squid DoS in external auth header parser
Hi,
* Vincent Danen <vdanen@...hat.com> [2009-07-20 19:48]:
> I noticed this on Debian's bts [1] and also on upstream's bugzilla [2]
> but no CVE has been assigned (not sure if one has been requested or not,
> but I've not seen a request come through here).
>
> By the initial looks of things, it seems to be a fairly low severity
> issue and may not be easy to duplicate/trigger. The reporter didn't really
> provide much in the way of a reproducer or relevant configs (and the
> reference to zope auths makes me not even want to touch it).
>
> Has anyone taken a look at this or has a CVE been requested for it?
CVE-2009-2622
CVE-2009-2621
Cheers
Nico
--
Nico Golde - http://www.ngolde.de - nion@...ber.ccc.de - GPG: 0xA0A0AAAA
For security reasons, all text in this mail is double-rot13 encrypted.
[ CONTENT OF TYPE application/pgp-signature SKIPPED ]
Powered by blists - more mailing lists
Please check out the
Open Source Software Security Wiki, which is counterpart to this
mailing list.
Powered by Openwall GNU/*/Linux -
Powered by OpenVZ