FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2005-0097

This CVE name corresponds to:

Entered Topic
2005-06-03 squid -- denial-of-service vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2005-0097
Phase Assigned(20050118)

Description

The NTLM component in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via a malformed NTLM type 3 message that triggers a NULL dereference.

References

Source Reference
CONFIRM http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-fakeauth_auth
FEDORA FLSA-2006:152809
GENTOO GLSA-200501-25
REDHAT RHSA-2005:060
REDHAT RHSA-2005:061
SUSE SUSE-SA:2005:006
TRUSTIX 2005-0003
BID 12220
OVAL oval:org.mitre.oval:def:11646
SECTRACK 1012818
SECUNIA 13789