FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2005-2917

This CVE name corresponds to:

Entered Topic
2005-09-15 squid -- possible denial of service condition regarding NTLM authentication

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2005-2917
Phase Assigned(20050915)

Description

Squid 2.5.STABLE10 and earlier, while performing NTLM authentication, does not properly handle certain request sequences, which allows attackers to cause a denial of service (daemon restart).

References

Source Reference
DEBIAN DSA-828
FEDORA FLSA-2006:152809
MANDRIVA MDKSA-2005:181
REDHAT RHSA-2006:0045
REDHAT RHSA-2006:0052
SCO SCOSA-2005.49
SGI 20060401-01-U
SUSE SUSE-SR:2005:027
UBUNTU USN-192-1
BID 14977
OSVDB 19607
OVAL oval:org.mitre.oval:def:11580
SECTRACK 1014920
SECUNIA 16992
SECUNIA 17015
SECUNIA 19161
SECUNIA 17050
SECUNIA 17177
SECUNIA 19532
XF squid-ntlm-authentication-dos(24282)