Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 447596 (CVE-2012-5643) - <net-proxy/squid-3.1.22: cachemgr.cgi Memory Leak Denial of Service Vulnerability (CVE-2012-5643)
Summary: <net-proxy/squid-3.1.22: cachemgr.cgi Memory Leak Denial of Service Vulnerabi...
Status: RESOLVED FIXED
Alias: CVE-2012-5643
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://secunia.com/advisories/51545/
Whiteboard: B3 [glsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2012-12-17 14:03 UTC by Agostino Sarubbo
Modified: 2013-09-27 09:52 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2012-12-17 14:03:14 UTC
From $URL :

Description
A vulnerability has been reported in Squid, which can be exploited by malicious users to cause a 
DoS (Denial of Service).

The vulnerability is caused due to memory leak errors within cachemgr.cgi (tools/cachemgr.cc) when 
handling certain requests, which can be exploited to consume resources and render the server 
unusable.

Successful exploitation requires access to cachemgr.cgi.

The vulnerability is reported in versions prior to 3.2.4 and 3.1.22.


Solution
Update to version 3.2.4 or 3.1.22.
Comment 1 Eray Aslan gentoo-dev 2012-12-17 19:20:01 UTC
+*squid-3.2.5 (17 Dec 2012)
+*squid-3.1.22 (17 Dec 2012)
+
+  17 Dec 2012; Eray Aslan <eras@gentoo.org> +files/squid.initd-logrotate-r2,
+  +files/squid.initd-r2, +squid-3.1.22.ebuild, +squid-3.2.5.ebuild:
+  Security bump - bug #447596
+

@security: We can stabilize =net-proxy/squid-3.1.22.  Thank you.
Comment 2 Agostino Sarubbo gentoo-dev 2012-12-17 19:24:07 UTC
Arches, please test and mark stable:
=net-proxy/squid-3.1.22
Target keywords : "alpha amd64 arm hppa ia64 ppc ppc64 sparc x86"
Comment 3 Agostino Sarubbo gentoo-dev 2012-12-18 15:46:43 UTC
amd64 stable
Comment 4 Agostino Sarubbo gentoo-dev 2012-12-18 15:47:22 UTC
x86 stable
Comment 5 Jeroen Roovers (RETIRED) gentoo-dev 2012-12-19 15:42:07 UTC
Stable for HPPA.
Comment 6 Agostino Sarubbo gentoo-dev 2012-12-22 15:19:42 UTC
ppc stable
Comment 7 GLSAMaker/CVETool Bot gentoo-dev 2012-12-23 00:48:28 UTC
CVE-2012-5643 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2012-5643):
  Multiple memory leaks in tools/cachemgr.cc in cachemgr.cgi in Squid 2.x and
  3.x before 3.1.22, 3.2.x before 3.2.4, and 3.3.x before 3.3.0.2 allow remote
  attackers to cause a denial of service (memory consumption) via (1) invalid
  Content-Length headers, (2) long POST requests, or (3) crafted
  authentication credentials.
Comment 8 Agostino Sarubbo gentoo-dev 2012-12-23 19:12:56 UTC
ppc64 stable
Comment 9 Markus Meier gentoo-dev 2012-12-24 12:17:34 UTC
arm stable
Comment 10 Agostino Sarubbo gentoo-dev 2012-12-25 22:24:36 UTC
ia64 stable
Comment 11 Agostino Sarubbo gentoo-dev 2012-12-28 15:07:55 UTC
sparc stable
Comment 12 Agostino Sarubbo gentoo-dev 2012-12-29 08:52:44 UTC
alpha stable
Comment 13 Sean Amoss (RETIRED) gentoo-dev Security 2012-12-29 13:24:51 UTC
GLSA vote: yes.
Comment 14 Tim Sammut (RETIRED) gentoo-dev 2013-01-02 18:41:02 UTC
GLSA Vote: yes, too. Added to existing GLSA request.
Comment 15 GLSAMaker/CVETool Bot gentoo-dev 2013-09-27 09:52:11 UTC
This issue was resolved and addressed in
 GLSA 201309-22 at http://security.gentoo.org/glsa/glsa-201309-22.xml
by GLSA coordinator Sergey Popov (pinkbyte).