Bugzilla – Bug 65895
VUL-0: CVE-2005-0446: more dos in squid
Last modified: 2021-11-30 14:56:50 UTC
From: Martin Schulze <joey@infodrom.org> To: Free Software Distribution Vendors <vendor-sec@lst.de> Subject: [vendor-sec] CAN-2005-0446: Denial of service in Squid FYI: http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE8-dns_assert http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE8-dns_assert.patch Regards, Joey
<!-- SBZ_reproduce --> n/a
Created attachment 28566 [details] squid.diff
Created attachment 28567 [details] squid-new.diff
Thomas, note that your patches are no good. They contain MIME encodings, e.g. "=3D" instead of "=". Don't see where the difference between original and yours are? But anyway, thanks for your work.
Note: The risk is only minor, as it can be reduced with Option "log_fqdn off" (the default setting)
New packages are submitted for all maintained SuSE versions: 8.1 (incl. SLES8, UL, SLEC), 8.2, 9.0, 9.1 (incl. SLES, SLD), 9.2 Reassigning to security-team for further processing.
Thanks. BTW, that were not my patches. :)
SM-Tracker-412
/work/src/done/PATCHINFO/squid.patch.maintained /work/src/done/PATCHINFO/squid.patch.box
fixed packages released.
CVE-2005-0446: CVSS v2 Base Score: 5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P)