<?xml version="1.0" encoding="UTF-8" ?>

<bugzilla version="5.2"
          urlbase="https://bugzilla.altlinux.org/"
          
          maintainer="jenya@basealt.ru"
>

    <bug>
          <bug_id>22869</bug_id>
          
          <creation_ts>2010-02-02 00:24:38 +0300</creation_ts>
          <short_desc>CVE-2010-0308: squid DoS in DNS handling</short_desc>
          <delta_ts>2010-10-21 12:14:03 +0400</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>4</classification_id>
          <classification>Development</classification>
          <product>Sisyphus</product>
          <component>squid</component>
          <version>unstable</version>
          <rep_platform>all</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>CLOSED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc>http://www.squid-cache.org/Advisories/SQUID-2010_1.txt</bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>security</keywords>
          <priority>P3</priority>
          <bug_severity>blocker</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Dmitry V. Levin">ldv</reporter>
          <assigned_to name="Alexey Shabalin">shaba</assigned_to>
          <cc>egori</cc>
    
    <cc>erthad</cc>
    
    <cc>rider</cc>
    
    <cc>shaba</cc>
          
          <qa_contact>qa-sisyphus</qa_contact>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>106233</commentid>
    <comment_count>0</comment_count>
    <who name="Dmitry V. Levin">ldv</who>
    <bug_when>2010-02-02 00:24:38 +0300</bug_when>
    <thetext>Squid upstream has released updated versions fixing DoS when processing specially crafted DNS packets.

The bug allows any trusted client or external server who can determine the squid receiving port to perform a short-term denial of service attack on the Squid service.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>106272</commentid>
    <comment_count>1</comment_count>
    <who name="Grigory Batalov">bga</who>
    <bug_when>2010-02-03 00:34:37 +0300</bug_when>
    <thetext>The package needs a new maintainer.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>114088</commentid>
    <comment_count>2</comment_count>
    <who name="Vitaly Kuznetsov">vitty</who>
    <bug_when>2010-10-21 12:14:03 +0400</bug_when>
    <thetext>fixed long ago</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>