CVE-2005-2917: Medium severity Squid Squid vulnerability
Published Sep 30, 2005
·Updated
Squid 2.5.STABLE10 and earlier, while performing NTLM authentication, does not properly handle certain request sequences, which allows attackers to cause a denial of service (daemon restart).
Affected Software
2 affected components
Squid Squid<=2.5.stable10
Squid Squid=2.5.9
Remediation
Patch Available
Patch Available
Event History
Sep 30, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-2917?
CVE-2005-2917 has a severity level indicating a denial of service risk that could restart the Squid daemon.
2
How do I fix CVE-2005-2917?
To fix CVE-2005-2917, upgrade to Squid version 2.5.STABLE11 or later.
3
What versions of Squid are affected by CVE-2005-2917?
CVE-2005-2917 affects Squid versions up to and including 2.5.STABLE10.
4
What type of attack does CVE-2005-2917 enable?
CVE-2005-2917 enables attackers to cause a denial of service through specific NTLM authentication request sequences.
5
Where can I find more information about CVE-2005-2917?
More information regarding CVE-2005-2917 can be found in security advisories related to the Squid Web Proxy Cache.