First published: Thu May 19 2011(Updated: )
Squid is a high-performance proxy caching server for web clients,<br>supporting FTP, Gopher, and HTTP data objects.<br>It was found that string comparison functions in Squid did not properly<br>handle the comparisons of NULL and empty strings. A remote, trusted web<br>client could use this flaw to cause the squid daemon to crash via a<br>specially-crafted request. (CVE-2010-3072)<br>This update also fixes the following bugs:<br><li> A small memory leak in Squid caused multiple "ctx: enter level" messages</li> to be logged to "/var/log/squid/cache.log". This update resolves the memory<br>leak. (BZ#666533)<br><li> This erratum upgrades Squid to upstream version 3.1.10. This upgraded</li> version supports the Google Instant service and introduces various code<br>improvements. (BZ#639365)<br>Users of squid should upgrade to this updated package, which resolves these<br>issues. After installing this update, the squid service will be restarted<br>automatically.<br>
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/squid | <3.1.10-1.el6 | 3.1.10-1.el6 |
redhat/squid | <3.1.10-1.el6 | 3.1.10-1.el6 |
redhat/squid-debuginfo | <3.1.10-1.el6 | 3.1.10-1.el6 |
redhat/squid-debuginfo | <3.1.10-1.el6 | 3.1.10-1.el6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.