aboutsummaryrefslogtreecommitdiffstats
path: root/security
diff options
context:
space:
mode:
authornectar <nectar@FreeBSD.org>2005-01-14 02:41:58 +0800
committernectar <nectar@FreeBSD.org>2005-01-14 02:41:58 +0800
commite8f09d25516d82b23ac83342847098f165c6fe45 (patch)
tree6c1aa18318d10229aa19e362b370e635a21e2db4 /security
parent9965ccbe9bbddc57edbd81e9f41ab7130a75fe6e (diff)
downloadfreebsd-ports-gnome-e8f09d25516d82b23ac83342847098f165c6fe45.tar.gz
freebsd-ports-gnome-e8f09d25516d82b23ac83342847098f165c6fe45.tar.zst
freebsd-ports-gnome-e8f09d25516d82b23ac83342847098f165c6fe45.zip
For recent squid WCCP DoS issue, correct the URL used in <blockquote>
"cite" attribute and <url> content. It referenced the wrong squid patch description.
Diffstat (limited to 'security')
-rw-r--r--security/vuxml/vuln.xml5
1 files changed, 3 insertions, 2 deletions
diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml
index f4668d79a090..1eafd9e7a024 100644
--- a/security/vuxml/vuln.xml
+++ b/security/vuxml/vuln.xml
@@ -129,7 +129,7 @@ EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
<description>
<body xmlns="http://www.w3.org/1999/xhtml">
<p>The squid patches page notes:</p>
- <blockquote cite="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-fakeauth_auth">
+ <blockquote cite="http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-wccp_denial_of_service">
<p>WCCP_I_SEE_YOU messages contain a 'number of caches'
field which should be between 1 and 32. Values outside
that range may crash Squid if WCCP is enabled, and if an
@@ -141,11 +141,12 @@ EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
</body>
</description>
<references>
- <url>http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-fakeauth_auth</url>
+ <url>http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE7-wccp_denial_of_service</url>
</references>
<dates>
<discovery>2005-01-07</discovery>
<entry>2005-01-12</entry>
+ <modified>2005-01-13</modified>
</dates>
</vuln>