First published: Fri Sep 30 2005(Updated: )
Squid 2.5.STABLE10 and earlier, while performing NTLM authentication, does not properly handle certain request sequences, which allows attackers to cause a denial of service (daemon restart).
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Squid Web Proxy Cache | <=2.5.stable10 | |
Squid Web Proxy Cache | =2.5.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2917 has a severity level indicating a denial of service risk that could restart the Squid daemon.
To fix CVE-2005-2917, upgrade to Squid version 2.5.STABLE11 or later.
CVE-2005-2917 affects Squid versions up to and including 2.5.STABLE10.
CVE-2005-2917 enables attackers to cause a denial of service through specific NTLM authentication request sequences.
More information regarding CVE-2005-2917 can be found in security advisories related to the Squid Web Proxy Cache.