First published: Tue Aug 30 2011(Updated: )
A flaw was reported [1] in how Squid parsed responses from Gopher servers. This flaw could result in a buffer overflow if a Gopher server were to return a line longer than 4096 bytes, leading to memory corruption and a crash. This flaw is an extension of SQUID-2005:1 (or <a href="https://access.redhat.com/security/cve/CVE-2005-0094">CVE-2005-0094</a>) in Squid 3.x, due to increased packet read sizes. A malicious user could setup a fake Gopher server and forward requests to it through Squid. A specially crafted response from that server could cause Squid to restart. This has been corrected in upstream versions 3.2.0.11, 3.1.15, and 3.0.STABLE26. Patches for 3.0 [2], 3.1 [3], and 3.2 [4] are available. [1] <a href="http://www.squid-cache.org/Advisories/SQUID-2011_3.txt">http://www.squid-cache.org/Advisories/SQUID-2011_3.txt</a> [2] <a href="http://www.squid-cache.org/Versions/v3/3.0/changesets/squid-3.0-9193.patch">http://www.squid-cache.org/Versions/v3/3.0/changesets/squid-3.0-9193.patch</a> [3] <a href="http://www.squid-cache.org/Versions/v3/3.1/changesets/squid-3.1-10363.patch">http://www.squid-cache.org/Versions/v3/3.1/changesets/squid-3.1-10363.patch</a> [4] <a href="http://www.squid-cache.org/Versions/v3/3.2/changesets/squid-3.2-11294.patch">http://www.squid-cache.org/Versions/v3/3.2/changesets/squid-3.2-11294.patch</a>
Affected Software | Affected Version | How to fix |
---|---|---|
Squid Web Proxy Cache | <3.2.0.11<3.1.15<3.0.STABLE26 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-734583 is high due to the potential for a buffer overflow and memory corruption.
To fix REDHAT-BUG-734583, upgrade to a version of Squid that is not vulnerable, specifically above versions 3.2.0.11, 3.1.15, and 3.0.STABLE26.
The affected versions in REDHAT-BUG-734583 include Squid versions up to 3.2.0.11, 3.1.15, and 3.0.STABLE26.
REDHAT-BUG-734583 affects the Squid web proxy when interacting with Gopher servers.
The potential impact of REDHAT-BUG-734583 includes memory corruption, which can lead to crashes of the Squid service.