Bug#514142: squid: denial of service via crafted request

2009-02-07 Thread Laurent Bonnaud
Hi, is this problem the same as the following one ? http://www.squid-cache.org/Advisories/SQUID-2009_1.txt If so, could you please put the SQUID-2009:1 reference in the Debian changelog ? BTW, why is there no CVE number for this bug ? -- Laurent Bonnaud.

Bug#514142: squid: denial of service via crafted request

2009-02-07 Thread Luigi Gangitano
As stated in the original bug report, this bug was reported by upstream security advisory SQUID-2009:1. Since the fix was upload via NMU by Steffen, I'll wait it's migration to lenny and then upload a new version with the advisory reference. Regards, L -- Luigi Gangitano --

Bug#514142: squid: denial of service via crafted request

2009-02-04 Thread Steffen Joeris
Package: squid Severity: grave Tags: security Justification: user security hole Hi A DoS issue has been reported[0] for squid. So far I cannot see the vulnerable code in the stable release, but it would be nice, if you could check that as well. Lenny seems to be affected and needs fixing. I've