Squid 2.5.STABLE10 and earlier, while performing NTLM authentication, does not properly handle certain request sequences, which allows attackers to cause a denial of service (daemon restart).
Name | Vendor | Start Version | End Version |
---|---|---|---|
Squid | Squid | * | 2.5.stable10 (including) |
Squid | Squid | 2.5.9 (including) | 2.5.9 (including) |
Red Hat Enterprise Linux 3 | RedHat | squid-7:2.5.STABLE3-6.3E.16 | * |
Red Hat Enterprise Linux 4 | RedHat | squid-7:2.5.STABLE6-3.4E.12 | * |
Squid | Ubuntu | dapper | * |
Squid | Ubuntu | devel | * |
Squid | Ubuntu | edgy | * |
Squid | Ubuntu | feisty | * |