FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2005-0094

This CVE name corresponds to:

Entered Topic
2005-01-12 squid -- buffer overflow vulnerability in gopherToHTML

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2005-0094
Phase Assigned(20050118)

Description

Buffer overflow in the gopherToHTML function in the Gopher reply parser for Squid 2.5.STABLE7 and earlier allows remote malicious Gopher servers to cause a denial of service (crash) via crafted responses.

References

Source Reference
CONFIRM http://www.squid-cache.org/Advisories/SQUID-2005_1.txt
CONFIRM http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE7-gopher_html_parsing.patch
CONECTIVA CLA-2005:923
DEBIAN DSA-651
FEDORA FLSA-2006:152809
GENTOO GLSA-200501-25
MANDRAKE MDKSA-2005:014
REDHAT RHSA-2005:060
REDHAT RHSA-2005:061
SUSE SUSE-SA:2005:006
TRUSTIX 2005-0003
BID 12276
OVAL oval:org.mitre.oval:def:11146
SECUNIA 13825