First published: Fri Sep 03 2010(Updated: )
A denial of service flaw was found in the way Squid proxy caching server internally processed NULL buffers. A remote, trusted client could use this flaw to cause squid daemon crash (dereference NULL pointer) when processing specially-crafted request. References: [1] <a href="http://www.squid-cache.org/Advisories/SQUID-2010_3.txt">http://www.squid-cache.org/Advisories/SQUID-2010_3.txt</a> Upstream patch (against Squid v3.0): [2] <a href="http://www.squid-cache.org/Versions/v3/3.0/changesets/squid-3.0-9189.patch">http://www.squid-cache.org/Versions/v3/3.0/changesets/squid-3.0-9189.patch</a> Upstream patch (against Squid v3.1): [3] <a href="http://www.squid-cache.org/Versions/v3/3.1/changesets/squid-3.1-10090.patch">http://www.squid-cache.org/Versions/v3/3.1/changesets/squid-3.1-10090.patch</a> Credit: The vulnerability was discovered by Phil Oester.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/squid | <7:3.1.10-1.el6 | 7:3.1.10-1.el6 |
Squid Web Proxy Cache | =3.0 | |
Squid Web Proxy Cache | =3.0.stable1 | |
Squid Web Proxy Cache | =3.0.stable2 | |
Squid Web Proxy Cache | =3.0.stable3 | |
Squid Web Proxy Cache | =3.0.stable4 | |
Squid Web Proxy Cache | =3.0.stable5 | |
Squid Web Proxy Cache | =3.0.stable6 | |
Squid Web Proxy Cache | =3.0.stable7 | |
Squid Web Proxy Cache | =3.0.stable8 | |
Squid Web Proxy Cache | =3.0.stable9 | |
Squid Web Proxy Cache | =3.0.stable10 | |
Squid Web Proxy Cache | =3.0.stable11 | |
Squid Web Proxy Cache | =3.0.stable11-rc1 | |
Squid Web Proxy Cache | =3.0.stable12 | |
Squid Web Proxy Cache | =3.0.stable13 | |
Squid Web Proxy Cache | =3.0.stable14 | |
Squid Web Proxy Cache | =3.0.stable15 | |
Squid Web Proxy Cache | =3.0.stable16 | |
Squid Web Proxy Cache | =3.0.stable16-rc1 | |
Squid Web Proxy Cache | =3.0.stable17 | |
Squid Web Proxy Cache | =3.0.stable18 | |
Squid Web Proxy Cache | =3.0.stable19 | |
Squid Web Proxy Cache | =3.0.stable20 | |
Squid Web Proxy Cache | =3.0.stable21 | |
Squid Web Proxy Cache | =3.0.stable22 | |
Squid Web Proxy Cache | =3.0.stable23 | |
Squid Web Proxy Cache | =3.0.stable24 | |
Squid Web Proxy Cache | =3.0.stable25 | |
Squid Web Proxy Cache | =3.1 | |
Squid Web Proxy Cache | =3.1.0.1 | |
Squid Web Proxy Cache | =3.1.0.2 | |
Squid Web Proxy Cache | =3.1.0.3 | |
Squid Web Proxy Cache | =3.1.0.4 | |
Squid Web Proxy Cache | =3.1.0.5 | |
Squid Web Proxy Cache | =3.1.0.6 | |
Squid Web Proxy Cache | =3.1.0.7 | |
Squid Web Proxy Cache | =3.1.0.8 | |
Squid Web Proxy Cache | =3.1.0.9 | |
Squid Web Proxy Cache | =3.1.0.10 | |
Squid Web Proxy Cache | =3.1.0.11 | |
Squid Web Proxy Cache | =3.1.0.12 | |
Squid Web Proxy Cache | =3.1.0.13 | |
Squid Web Proxy Cache | =3.1.0.14 | |
Squid Web Proxy Cache | =3.1.0.15 | |
Squid Web Proxy Cache | =3.1.0.16 | |
Squid Web Proxy Cache | =3.1.0.17 | |
Squid Web Proxy Cache | =3.1.0.18 | |
Squid Web Proxy Cache | =3.1.1 | |
Squid Web Proxy Cache | =3.1.2 | |
Squid Web Proxy Cache | =3.1.3 | |
Squid Web Proxy Cache | =3.1.4 | |
Squid Web Proxy Cache | =3.1.5 | |
Squid Web Proxy Cache | =3.1.5.1 | |
Squid Web Proxy Cache | =3.1.6 | |
Squid Web Proxy Cache | =3.1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.