Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 106104 - net-proxy/squid another potential ntlm issue
Summary: net-proxy/squid another potential ntlm issue
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL: http://www.squid-cache.org/Versions/v...
Whiteboard: C3 [noglsa] jaervosz
Keywords:
Depends on:
Blocks:
 
Reported: 2005-09-15 13:37 UTC by Sune Kloppenborg Jeppesen (RETIRED)
Modified: 2005-09-19 01:02 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-09-15 13:37:58 UTC
FATAL: Incorrect scheme in auth header 
 
Squid may crash with the above error when given certain request sequences.
Comment 1 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-09-15 13:38:43 UTC
net-proxy please advise and bump as necessary. 
Comment 2 Alin Năstac (RETIRED) gentoo-dev 2005-09-16 01:45:18 UTC
seems like DoS to me.
I will bump the revision tonight (my time is GMT+3)
Comment 3 Alin Năstac (RETIRED) gentoo-dev 2005-09-16 11:17:13 UTC
r4 submitted to the tree.
it was tested and marked stable on x86 by myself.
Comment 4 Thierry Carrez (RETIRED) gentoo-dev 2005-09-17 06:19:01 UTC
Arches, please test and mark -r4 stable
Comment 5 Luis Medinas (RETIRED) gentoo-dev 2005-09-17 06:56:07 UTC
Marked Stable on amd64.
Comment 6 Michael Hanselmann (hansmi) (RETIRED) gentoo-dev 2005-09-17 11:14:23 UTC
Stable on ppc and hppa.
Comment 7 Jason Wever (RETIRED) gentoo-dev 2005-09-17 17:15:54 UTC
SPARC'd
Comment 8 Markus Rothe (RETIRED) gentoo-dev 2005-09-18 00:02:15 UTC
stable on ppc64 
Comment 9 Thierry Carrez (RETIRED) gentoo-dev 2005-09-18 02:24:35 UTC
Ready for GLSA vote
Comment 10 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-09-19 00:31:30 UTC
I think we should wait for further issues -> voting NO. 
Comment 11 Thierry Carrez (RETIRED) gentoo-dev 2005-09-19 01:02:57 UTC
Voting no too, we usually don't have to wait very long for more issues ti pile
up on squid.