[22706] in bugtraq

home help back first fref pref prev next nref lref last post

squid DoS

daemon@ATHENA.MIT.EDU (Vladimir Ivaschenko)
Fri Sep 21 14:33:39 2001

Message-ID: <3BAAFEEE.1F92261E@francoudi.com>
Date: Fri, 21 Sep 2001 11:48:47 +0300
From: Vladimir Ivaschenko <hazard@francoudi.com>
MIME-Version: 1.0
To: bugtraq@securityfocus.com
Content-Type: text/plain; charset=koi8-r
Content-Transfer-Encoding: 7bit

Dear All,

I'd like to inform about a DoS bug I recently found in SQUID regarding
handling of mkdir-only PUT requests - please look at
http://www.squid-cache.org/bugs/show_bug.cgi?id=233 for more info.
From my testing, it applies both to Squid 2.3 and 2.4 series. Tested on
RedHat 6.2 and 7.1.

This bug has been fixed by SQUID developers on Sep 18 and has been known
for about two weeks - I think its time to inform Bugtraq.

--
Best Regards
Vladimir Ivaschenko
Certified Linux Engineer (RHCE)
http://www.hazard.maks.net/


home help back first fref pref prev next nref lref last post