Reg. Squid vulnerabilities

From: Balamurugan <bmurugan@dont-contact.us>
Date: Wed, 19 Oct 2005 16:29:15 +0530

Hello Squid Developers,

Advanced thanks for your help!

The following two squid vulnerabilities were found in the September month
this year.

1) Squid "storeBuffer()" Denial of Service Vulnerability
(http://secunia.com/advisories/16708/)
2) Squid NTLM Authentication Handling Denial of Service
(http://secunia.com/advisories/16992/)

I hope "storeBuffer() Denial of Service Vulnerability" has been fixed in
Squid-2.5.STABLE11.

Squid-2.5.STABLE11 was released before declaring the "NTLM Authentication
Handling Denial of Service vulnerability". But patch is available only for
Squid-2.5.STABLE10.

Is Squid-2.5.STABLE11 also affected by this vulnerability? If so, any patch
is available for Squid-2.5.STABLE11?

Best Regards,
-- Balamurugan.
Received on Wed Oct 19 2005 - 13:55:39 MDT

This archive was generated by hypermail pre-2.1.9 : Tue Nov 01 2005 - 12:00:07 MST