Summary: | net-www/squid - Cache NTLM Authentication Helper Buffer Overflow Vulnerability | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Carsten Lohrke (RETIRED) <carlo> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | major | CC: | andrewbevitt, ppc |
Priority: | High | Flags: | jaervosz:
Assigned_To?
(jaervosz) |
Version: | unspecified | ||
Hardware: | All | ||
OS: | All | ||
Whiteboard: | C1 [glsa] | ||
Package list: | Runtime testing required: | --- |
Description
Carsten Lohrke (RETIRED)
2004-06-08 17:50:21 UTC
CAN-2004-0541 I think the default is not to use NTLM auth cache helper so I rated this as C1 rather than B1. Andrew: could you apply the patch provided at : http://www.squid-cache.org/~wessels/patch/libntlmssp.c.patch and bump to 2.5.5-r2 ? Please also confirm if default configuration files shipped in Gentoo enable the NTLM auth cache helper or not... Thanks ! Right, it's compiled in, but not enabled by default. OK fix now just gone into CVS... x86 ppc sparc alpha hppa ia64: please mark stable Stable on alpha. Stable on hppa. Stable on sparc. Stable on x86. GLSA drafted: security please review ppc please mark stable Please remove old unneeded versions from portage. ia64 also remember to mark stable. Stable on ppc. waiting for ia64 to mark stable glsa 200406-13 |