Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 216319 (CVE-2008-1612) - net-proxy/squid <2.6.18 arrayShrink assert Denial of Service (CVE-2008-1612)
Summary: net-proxy/squid <2.6.18 arrayShrink assert Denial of Service (CVE-2008-1612)
Status: RESOLVED FIXED
Alias: CVE-2008-1612
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High minor (vote)
Assignee: Gentoo Security
URL: http://marc.info/?l=squid-announce&m=...
Whiteboard: B3 [glsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2008-04-05 13:01 UTC by Robert Buchholz (RETIRED)
Modified: 2009-03-24 21:45 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Buchholz (RETIRED) gentoo-dev 2008-04-05 13:01:57 UTC
CVE-2008-1612 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1612):
  The arrayShrink function (lib/Array.c) in Squid 2.6.STABLE17 allows attackers
  to cause a denial of service (process exit) via unknown vectors that cause an
  array to shrink to 0 entries, which triggers an assert error.  NOTE: this
  issue is due to an incorrect fix for CVE-2007-6239.
Comment 1 Robert Buchholz (RETIRED) gentoo-dev 2008-04-05 13:03:01 UTC
Net-proxy, since 2.6.18 is already in the tree, can we stable it?
Comment 2 Alin Năstac (RETIRED) gentoo-dev 2008-04-11 19:24:34 UTC
Of course you can.
Comment 3 Robert Buchholz (RETIRED) gentoo-dev 2008-04-11 19:35:05 UTC
Arches, please test and mark stable:
=net-proxy/squid-2.6.18
Target keywords : "alpha amd64 hppa ia64 ppc ppc64 release sparc x86"
Comment 4 Markus Meier gentoo-dev 2008-04-11 21:09:03 UTC
amd64/x86 stable
Comment 5 Markus Rothe (RETIRED) gentoo-dev 2008-04-12 08:09:40 UTC
ppc64 stable
Comment 6 Raúl Porcel (RETIRED) gentoo-dev 2008-04-12 17:10:17 UTC
alpha/ia64/sparc stable
Comment 7 Jeroen Roovers (RETIRED) gentoo-dev 2008-04-12 17:18:24 UTC
Stable for HPPA.
Comment 8 Tobias Scherbaum (RETIRED) gentoo-dev 2008-04-12 17:52:53 UTC
ppc stable
Comment 9 Robert Buchholz (RETIRED) gentoo-dev 2008-04-15 23:01:25 UTC
I think this warrants an errata for GLSA 200801-05.
Comment 10 Peter Volkov (RETIRED) gentoo-dev 2008-04-21 07:48:17 UTC
Fixed in release snapshot.
Comment 11 Alin Năstac (RETIRED) gentoo-dev 2008-12-14 14:18:49 UTC
Shouldn't this bug be closed by now?
Comment 12 martin holzer 2009-02-06 11:54:17 UTC
you can close this

there's a new bug #257585
Comment 13 Pierre-Yves Rofes (RETIRED) gentoo-dev 2009-03-24 21:45:50 UTC
GLSA 200903-38, sorry for the delay...