Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.55495
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-828-1)
Summary:The remote host is missing an update for the Debian 'squid' package(s) announced via the DSA-828-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'squid' package(s) announced via the DSA-828-1 advisory.

Vulnerability Insight:
Upstream developers of squid, the popular WWW proxy cache, have discovered that changes in the authentication scheme are not handled properly when given certain request sequences while NTLM authentication is in place, which may cause the daemon to restart.

The old stable distribution (woody) is not affected by this problem.

For the stable distribution (sarge) this problem has been fixed in version 2.5.9-10sarge2.

For the unstable distribution (sid) this problem has been fixed in version 2.5.10-6.

We recommend that you upgrade your squid packages.

Affected Software/OS:
'squid' package(s) on Debian 3.1.

Solution:
Please install the updated package(s).

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2005-2917
1014920
http://securitytracker.com/id?1014920
14977
http://www.securityfocus.com/bid/14977
16992
http://secunia.com/advisories/16992
17015
http://secunia.com/advisories/17015
17050
http://secunia.com/advisories/17050
17177
http://secunia.com/advisories/17177
19161
http://secunia.com/advisories/19161
19532
http://secunia.com/advisories/19532
19607
http://www.osvdb.org/19607
20060401-01-U
ftp://patches.sgi.com/support/free/security/advisories/20060401-01-U
DSA-828
http://www.debian.org/security/2005/dsa-828
FLSA-2006:152809
http://fedoranews.org/updates/FEDORA--.shtml
MDKSA-2005:181
http://www.mandriva.com/security/advisories?name=MDKSA-2005:181
RHSA-2006:0045
http://www.redhat.com/support/errata/RHSA-2006-0045.html
RHSA-2006:0052
http://www.redhat.com/support/errata/RHSA-2006-0052.html
SCOSA-2005.49
ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt
SUSE-SR:2005:027
http://www.novell.com/linux/security/advisories/2005_27_sr.html
USN-192-1
http://www.ubuntu.com/usn/usn-192-1/
oval:org.mitre.oval:def:11580
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11580
squid-ntlm-authentication-dos(24282)
https://exchange.xforce.ibmcloud.com/vulnerabilities/24282
CopyrightCopyright (C) 2008 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.