Source: squid3
Version: 3.1.6-1.2
Severity: normal
Tags: security upstream patch

Hi

See [1] for a remote DoS reported by Sebastian Krahmer.

 [1] https://bugzilla.novell.com/show_bug.cgi?id=891268

> The pinger code that checks for nodes being alive doesnt
> properly validate ICMP and ICMPv6 replies, in particular
> icmp6 types which are used to index into a string array.
> This could cause crashes when the index is OOB.
[...]

No CVE is assigned yet for this issue.

Regards,
Salvatore

_______________________________________________
Secure-testing-team mailing list
[email protected]
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/secure-testing-team

Reply via email to