Bug 59696 (CVE-2004-0832) - VUL-0: CVE-2004-0832: CVE-2004-0832DoS in squid NTLM authentication
Summary: VUL-0: CVE-2004-0832: CVE-2004-0832DoS in squid NTLM authentication
Status: RESOLVED FIXED
Alias: CVE-2004-0832
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: All Linux
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Ludwig Nussel
QA Contact: Security Team bot
URL:
Whiteboard: CVE-2004-0832: CVSS v2 Base Score: 5....
Keywords:
Depends on:
Blocks:
 
Reported: 2004-09-03 23:18 UTC by Ludwig Nussel
Modified: 2021-10-16 09:02 UTC (History)
1 user (show)

See Also:
Found By: ---
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments
/work/src/done/PATCHINFO/squid.patch.box (374 bytes, text/plain)
2004-09-10 18:11 UTC, Ludwig Nussel
Details
/work/src/done/PATCHINFO/squid.patch.maintained (407 bytes, text/plain)
2004-09-10 18:12 UTC, Ludwig Nussel
Details

Note You need to log in before you can comment on or make changes to this bug.
Description Ludwig Nussel 2004-09-03 23:18:01 UTC
Heise reports about a DoS in squid's NTLM authentication
http://www1.uk.squid-cache.org/squid/Versions/v2/2.5/bugs/#squid-2.5.STABLE6-ntlm_fetch_string

Apparently you have already applied this patch in STABLE. Are
released versions not affected or is it just a different patch for
an old issue?
Comment 1 Klaus Singvogel 2004-09-06 18:33:33 UTC
Yes, I updated STABLE recently. :-) 
 
According to Heise all of our maintained versions are affected. 
According to the specfiles (grep'ed for ntlm :-), 2.5.STABLE1 and later is 
affected: SuLi 8.2, 8.3, 9.0, 9.1, SLES9, and maybe other products? 
 
Bad news: I don't know how important that stuff is, but I don't have 
enough time to fix it within this week (2004-09-06 - 2004-09-12). 
Comment 2 Klaus Singvogel 2004-09-09 21:28:55 UTC
CAN-2004-0832 
Comment 3 Klaus Singvogel 2004-09-09 21:48:48 UTC
Patches made and submited. 
 
Patch-management: I don't have a Windows, so I cannot test. Please test 
any version. TIA. 
 
Security-team: please handle rest of process: putonftp, patchinfo, etc. 
Comment 4 Ludwig Nussel 2004-09-10 18:11:54 UTC
Created attachment 23302 [details]
/work/src/done/PATCHINFO/squid.patch.box

8.2,9.0,9.1
Comment 5 Ludwig Nussel 2004-09-10 18:12:08 UTC
Created attachment 23303 [details]
/work/src/done/PATCHINFO/squid.patch.maintained

sles9
Comment 6 Thomas Biege 2004-09-13 19:20:04 UTC
reassigned to Ludwig for the ease of tracking this issue. 
Comment 7 Thomas Biege 2004-09-23 20:41:12 UTC
packages were approved... 
Comment 8 Thomas Biege 2009-10-13 19:49:34 UTC
CVE-2004-0832: CVSS v2 Base Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P)