FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2005-0718

This CVE name corresponds to:

Entered Topic
2005-04-10 squid -- DoS on failed PUT/POST requests vulnerability

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2005-0718
Phase Assigned(20050312)

Description

Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (segmentation fault) by aborting the connection during a (1) PUT or (2) POST request, which causes Squid to access previously freed memory.

References

Source Reference
CONFIRM http://www.squid-cache.org/bugs/show_bug.cgi?id=1224
CONFIRM http://www1.uk.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-post
CONECTIVA CLA-2005:931
FEDORA FLSA-2006:152809
REDHAT RHSA-2005:415
REDHAT RHSA-2005:489
UBUNTU USN-111-1
BID 13166
SECUNIA 12508
XF squid-put-post-dos(19919)