First Last Prev Next    No search results available      Search page      Enter new bug
Bug#: 162364
Alias:
Product:
Component:
Status: RESOLVED
Resolution: FIXED
Assigned To: Gentoo Security <security@gentoo.org>
Hardware:
OS:
Version:
Priority:
Severity:
Reporter: Executioner <keith@email.arizona.edu>
Add CC:
CC:
Remove selected CCs
URL:
Summary:
Status Whiteboard:
Keywords:
Flags: Requestee:
 
 
  ()

Filename Description Type Creator Created Size Actions
Create a New Attachment (proposed patch, testcase, etc.) View All

Bug 162364 depends on: Show dependency tree
Bug 162364 blocks:

Additional Comments: (this is where you put emerge --info)


Not eligible to see or edit group visibility for this bug.






View Bug Activity   |   Format For Printing   |   XML   |   Clone This Bug


Description:   Opened: 2007-01-16 14:19 0000
Two vulnerabilities have been reported in Squid, which can be exploited by
malicious people to cause a DoS (Denial of Service).

1) An error in the handling of certain FTP URL requests can be exploited to
crash Squid by visiting a specially crafted FTP URL via the proxy.

2) An error in the external_acl queue can cause Squid to crash when it is under
high load conditions.

The vulnerabilities are reported in version 2.6. Other versions may also be
affected.

Solution:
Update to version 2.6.STABLE7.

Reproducible: Didn't try




http://www.squid-cache.org/Versions/v2/2.6/squid-2.6.STABLE7-RELEASENOTES.html#s12

------- Comment #1 From Jakub Moc (RETIRED) 2007-01-16 14:20:40 0000 -------
2.6.7 already in the tree; just needs to be stabilized...

------- Comment #2 From Raphael Marichez 2007-01-16 18:51:29 0000 -------
Hi arches, please test and mark stable squid-2.6.7 if possible, thanks

------- Comment #3 From Raúl Porcel 2007-01-16 23:09:30 0000 -------
x86 stable

------- Comment #4 From Jason Wever (RETIRED) 2007-01-16 23:41:17 0000 -------
Stable on SPARC

------- Comment #5 From Markus Rothe 2007-01-17 07:49:27 0000 -------
ppc64 stable

------- Comment #6 From Bryan Østergaard (RETIRED) 2007-01-18 03:15:40 0000 -------
Stable on Alpha.

------- Comment #7 From Jeroen Roovers 2007-01-18 08:07:10 0000 -------
Marked stable for HPPA by killerfox.

------- Comment #8 From Tobias Scherbaum 2007-01-18 21:02:43 0000 -------
ppc stable

------- Comment #9 From Alexander Færøy 2007-01-19 18:37:06 0000 -------
Stable on IA64.

------- Comment #10 From Alexander Færøy 2007-01-20 16:48:44 0000 -------
Stable on MIPS.

------- Comment #11 From Alin Năstac 2007-01-21 07:34:15 0000 -------
Marked stable on amd64.

------- Comment #12 From Raphael Marichez 2007-01-22 12:58:35 0000 -------
thanks arches

GLSA vote

I vote a full-yes since it's a squid DoS!!!

------- Comment #13 From Matthias Geerdsen 2007-01-22 16:59:24 0000 -------
voting yes, filing draft request

------- Comment #14 From Matthias Geerdsen 2007-01-25 21:01:44 0000 -------
GLSA 200701-22

thanks everyone

First Last Prev Next    No search results available      Search page      Enter new bug