Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 89149 - www-proxy/squid Unexpected access control results on configuration errors
Summary: www-proxy/squid Unexpected access control results on configuration errors
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All All
: High minor (vote)
Assignee: Gentoo Security
URL: http://www1.uk.squid-cache.org/Versio...
Whiteboard: B4? [noglsa] jaervosz
Keywords:
Depends on:
Blocks:
 
Reported: 2005-04-14 22:43 UTC by Sune Kloppenborg Jeppesen (RETIRED)
Modified: 2020-04-06 20:47 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-04-14 22:43:21 UTC
 
Comment 1 Alin Năstac (RETIRED) gentoo-dev 2005-04-15 00:57:12 UTC
This patch is already applied in 2.5.9-r2, along with many others
Comment 2 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-04-15 01:45:23 UTC
Is 2.5.9-r2 ready for arches to mark stable?
Comment 3 Alin Năstac (RETIRED) gentoo-dev 2005-04-15 02:11:52 UTC
Yes.

I prefer to set this version as stable because I changed the ebuild to apply customlog patch only when correspondent use flag is set. One user complained about memory leaks on versions with customlog patch applied - see bug 85740 for more info.
Comment 4 Thierry Carrez (RETIRED) gentoo-dev 2005-04-15 10:25:04 UTC
What about this one ? Is is covered ? Since when ?

===========================================================
Ubuntu Security Notice USN-111-1	     April 14, 2005
squid vulnerability
CAN-2005-0718
===========================================================
[...]
A remote Denial of Service vulnerability has been discovered in Squid.
If the remote end aborted the connection during a PUT or POST request,
Squid tried to free an already freed part of memory, which eventually
caused the server to crash.
Comment 5 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-04-15 10:31:32 UTC
Koon, that was what triggered me in the first place. AFAIR it only applies to patch level 7 and we are at patch level 9.
Comment 6 Alin Năstac (RETIRED) gentoo-dev 2005-04-16 04:10:01 UTC
their (ubuntu) version of squid is way too old. I've applied in 2.5.9-r2 all current patches up to "rename() related cleanup", which means we have all current patches applied excepting the last 3 cosmetic patches.
Comment 7 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-04-16 06:08:01 UTC
Arches please test and mark squid-2.5.9-r2 stable.
Comment 8 Jan Brinkmann (RETIRED) gentoo-dev 2005-04-16 06:33:39 UTC
stable on amd64
Comment 9 Michael Hanselmann (hansmi) (RETIRED) gentoo-dev 2005-04-16 07:27:22 UTC
Stable on ppc.
Comment 10 Alin Năstac (RETIRED) gentoo-dev 2005-04-17 02:20:59 UTC
stable on x86
Comment 11 Markus Rothe (RETIRED) gentoo-dev 2005-04-17 03:26:40 UTC
stable on ppc64
Comment 12 Jason Wever (RETIRED) gentoo-dev 2005-04-17 10:58:10 UTC
Stable on SPARC.
Comment 13 Alin Năstac (RETIRED) gentoo-dev 2005-04-19 03:53:31 UTC
r2 have been replaced by r3 due to bug #89586.
arches, please don't mark this as stable till I get confirmation that bug #89586 is fixed.
Comment 14 Bryan Østergaard (RETIRED) gentoo-dev 2005-04-19 12:49:20 UTC
Stable on alpha + ia64.
Comment 15 Thierry Carrez (RETIRED) gentoo-dev 2005-04-19 13:38:38 UTC
Voting no to GLSA
Comment 16 Sune Kloppenborg Jeppesen (RETIRED) gentoo-dev 2005-04-19 14:35:03 UTC
Voting for no GLSA as well on this one. Let's see if enough bugs pile up to warrant a GLSA. Also in the queue bug #83955
Comment 17 Alin Năstac (RETIRED) gentoo-dev 2005-04-19 15:11:32 UTC
damn! I was so close to cleanup older versions of squid...
now I must wait again >:-|
Comment 18 René Nussbaumer (RETIRED) gentoo-dev 2005-06-26 07:59:11 UTC
Stable on hppa