|
Bugzilla – Full Text Bug Listing |
| Summary: | VUL-0: CVE-2004-0918: squid SNMP module remote denial of service | ||
|---|---|---|---|
| Product: | [Novell Products] SUSE Security Incidents | Reporter: | Ludwig Nussel <lnussel> |
| Component: | Incidents | Assignee: | Security Team bot <security-team> |
| Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
| Severity: | Normal | ||
| Priority: | P3 - Medium | CC: | security-team |
| Version: | unspecified | ||
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | CVE-2004-0918: CVSS v2 Base Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P) | ||
| Found By: | --- | Services Priority: | |
| Business Priority: | Blocker: | --- | |
| Marketing QA Status: | --- | IT Deployment: | --- |
| Attachments: |
squid.patch.maintained
squid.patch.box |
||
|
Description
Marcus Meissner
2004-10-13 23:12:58 UTC
<!-- SBZ_reproduce --> n/a fixed packages submited for: 9.2, 9.1/SLES9, 9.0, 8.2, 8.1/SLES8/UL Test-Team: didn't test anything, but upstream patch run in flawless and builds fine. Security-Team: please handle rest of update process: patchinfo, putonftp... - Thanks in advance. <!-- SBZ_reopen -->Reopened by lnussel@suse.de at Thu Oct 14 15:18:54 2004, took initial reporter meissner@suse.de to cc reopen for reassign For the record. SNMP is not enabled in the default config, correct? Ludwig: you are wrong. Its enabled per default, as it is very useful. But if I understand the problem correct, then the vulnerability is present as soon as SNMP is compiled in (see above: "IV. DETECTION"). This is the case for all of our versions. Created attachment 25118 [details]
squid.patch.maintained
Created attachment 25119 [details]
squid.patch.box
updates released. CVE-2004-0918: CVSS v2 Base Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P) |