Bug 65895 (CVE-2005-0446)

Summary: VUL-0: CVE-2005-0446: more dos in squid
Product: [Novell Products] SUSE Security Incidents Reporter: Marcus Meissner <meissner>
Component: IncidentsAssignee: Security Team bot <security-team>
Status: RESOLVED FIXED QA Contact: Security Team bot <security-team>
Severity: Normal    
Priority: P3 - Medium CC: security-team
Version: unspecified   
Target Milestone: ---   
Hardware: All   
OS: Linux   
Whiteboard: CVE-2005-0446: CVSS v2 Base Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P)
Found By: Other Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---
Attachments: squid.diff
squid-new.diff

Description Marcus Meissner 2005-02-16 17:39:30 UTC
From: Martin Schulze <joey@infodrom.org> 
To: Free Software Distribution Vendors <vendor-sec@lst.de> 
Subject: [vendor-sec] CAN-2005-0446: Denial of service in Squid 
 
FYI: 
 
http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE8-dns_assert 
http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE8-dns_assert.patch 
 
Regards, 
 
        Joey
Comment 1 Marcus Meissner 2005-02-16 17:39:30 UTC
<!-- SBZ_reproduce  -->
n/a
Comment 2 Thomas Biege 2005-02-17 16:31:21 UTC
Created attachment 28566 [details]
squid.diff
Comment 3 Thomas Biege 2005-02-17 16:32:22 UTC
Created attachment 28567 [details]
squid-new.diff
Comment 4 Klaus Singvogel 2005-02-17 18:24:26 UTC
Thomas, note that your patches are no good. They contain MIME encodings, e.g. 
"=3D" instead of "=". 
 
Don't see where the difference between original and yours are? 
 
But anyway, thanks for your work. 
Comment 5 Klaus Singvogel 2005-02-17 18:57:26 UTC
Note: The risk is only minor, as it can be reduced with Option "log_fqdn 
off" (the default setting) 
Comment 6 Klaus Singvogel 2005-02-17 19:26:41 UTC
New packages are submitted for all maintained SuSE versions: 
8.1 (incl. SLES8, UL, SLEC), 8.2, 9.0, 9.1 (incl. SLES, SLD), 9.2 
 
Reassigning to security-team for further processing. 
Comment 7 Thomas Biege 2005-02-17 22:42:20 UTC
Thanks. BTW, that were not my patches. :) 
Comment 8 Thomas Biege 2005-02-17 23:06:00 UTC
 SM-Tracker-412 
Comment 9 Thomas Biege 2005-02-17 23:14:09 UTC
/work/src/done/PATCHINFO/squid.patch.maintained 
/work/src/done/PATCHINFO/squid.patch.box 
Comment 10 Marcus Meissner 2005-02-21 17:03:30 UTC
fixed packages released. 
Comment 11 Thomas Biege 2009-10-13 21:06:52 UTC
CVE-2005-0446: CVSS v2 Base Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P)