>> Debian Security Update Fixes Squid Denial of Service Vulnerability
Title : Debian Security Update Fixes Squid Denial of Service Vulnerability VUPEN ID : VUPEN/ADV-2005-1898 CVE ID : CVE-2005-2917 CWE ID : CWE-
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2005-09-30
Technical Description
Debian has released updated packages to correct a vulnerability identified in Squid. This flaw is due to an error in "authenticate.c" and "auth_ntlm.c" when handling changes in the authentication scheme while using NTLM authentication, which could be exploited by remote attackers to cause a denial of service via a specially crafted request.