Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 105166 - net-proxy/squid: "storeBuffer()" Denial of Service Vulnerability
Summary: net-proxy/squid: "storeBuffer()" Denial of Service Vulnerability
Status: RESOLVED DUPLICATE of bug 104603
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://secunia.com/advisories/16708/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2005-09-07 10:14 UTC by Jean-François Brunette (RETIRED)
Modified: 2005-09-07 10:51 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Jean-François Brunette (RETIRED) gentoo-dev 2005-09-07 10:14:32 UTC
Description:
Nickolay has reported a vulnerability in Squid, which potentially can be
exploited by malicious people to cause a DoS (Denial of Service).

The vulnerability is caused due to an unspecified error in the use of the
"storeBuffer()" function when handling aborted requests. This may be exploited
to crash Squid.

Solution:
Apply patch for 2.5.STABLE10:
http://www.squid-cache.org/Versi...2.5.STABLE10-STORE_PENDING.patch

Provided and/or discovered by:
Nickolay

Original Advisory:
http://www.squid-cache.org/Versi...squid-2.5.STABLE10-STORE_PENDING
Comment 1 Jean-François Brunette (RETIRED) gentoo-dev 2005-09-07 10:42:30 UTC
I would like to be sure if it has been patched with the bug 104603 ?
Comment 2 Jean-François Brunette (RETIRED) gentoo-dev 2005-09-07 10:51:44 UTC
The patch is in squid-2.5.STABLE10-patches-20050902.tar.gz, so I guess it has
been applied. Sorry

*** This bug has been marked as a duplicate of 104603 ***