RHSA-2010:0221: Low: squid security and bug fix update
Squid is a high-performance proxy caching server for web clients,supporting FTP, Gopher, and HTTP data objects.A flaw was found in the way Squid processed certain external ACL helperHTTP header fields that contained a delimiter that was not a comma. Aremote attacker could issue a crafted request to the Squid server, causingexcessive CPU use (up to 100%). (CVE-2009-2855)Note: The CVE-2009-2855 issue only affected non-default configurations thatuse an external ACL helper script.A flaw was found in the way Squid handled truncated DNS replies. A remoteattacker able to send specially-crafted UDP packets to Squid's DNS clientport could trigger an assertion failure in Squid's child process, causingthat child process to exit. (CVE-2010-0308)This update also fixes the following bugs: Squid's init script returns a non-zero value when trying to stop a stopped service. This is not LSB compliant and can generate difficulties incluster environments. This update makes stopping LSB compliant. (BZ#521926) Squid is not currently built to support MAC address filtering in ACLs. This update includes support for MAC address filtering. (BZ#496170) Squid is not currently built to support Kerberos negotiate authentication. This update enables Kerberos authentication. (BZ#516245) Squid does not include the port number as part of URIs it constructs when configured as an accelerator. This results in a 403 error. This updatecorrects this behavior. (BZ#538738) the errormap feature does not work if the same handling is set also on the HTTP server that operates in deflate mode. This update fixes thisissue. (BZ#470843)All users of squid should upgrade to this updated package, which resolvesthese issues. After installing this update, the squid service will berestarted automatically.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2010:0221?
The severity of RHSA-2010:0221 is considered important due to the potential for remote code execution.
How do I fix RHSA-2010:0221?
To fix RHSA-2010:0221, upgrade the Squid package to version 2.6.STABLE21-6.el5 or later.
Which versions of Squid are affected by RHSA-2010:0221?
Affected versions of Squid include all versions prior to 2.6.STABLE21-6.el5.
Can RHSA-2010:0221 be exploited remotely?
Yes, RHSA-2010:0221 can be exploited remotely by attackers targeting the Squid proxy server.
What does RHSA-2010:0221 address?
RHSA-2010:0221 addresses a flaw in Squid's handling of certain HTTP header fields leading to potential security risks.