Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Date: Tue, 1 Apr 2008 12:13:22 -0400 (EDT)
From: "Steven M. Christey" <>
To: Tomas Hoger <>
cc: "Steven M. Christey" <>,
        oss-security <>
Subject: Re: CVE id request: squid

Notice the reference to oss-security :)

- Steve

Name: CVE-2008-1612
Status: Candidate
Reference: MISC:
Reference: CONFIRM:
Reference: MLIST:[oss-security] 20080401 CVE id request: squid
Reference: URL:
Reference: MLIST:[squid-announce[ 20080322 Advisory Squid-2007:2 updated
Reference: URL:

The arrayShrink function (lib/Array.c) in Squid 2.6.STABLE17 allows
attackers to cause a denial of service (process exit) via unknown
vectors that cause an array to shrink to 0 entries, which triggers an
assert error.  NOTE: this issue is due to an incorrect fix for

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.