Due to an internal error Squid is vulnerable to a denial of service attack when processing specially crafted requests.
Determining if your version is vulnerable:
All Squid-2.7 versions up to, and including 2.7.STABLE5 are
vulnerable.
All Squid-3.0 versions up to and including 3.0.STABLE12 are
vulnerable.
All Squid-3.1 beta versions up to and including 3.1.0.4 are
vulnerable.
Squid 2.7 -> 2.7.STABLE5,
Squid 3.0 -> 3.0.STABLE12,
Squid 3.1 -> 3.1.0.4
Updated Packages:
This bug is fixed by Squid versions 2.7.STABLE6, 3.0.STABLE13,
and 3.1.0.5.
In addition, patches addressing this problem can be found In
our patch archives:
Squid 2.7:
<a href=http://www.squid-cache.org/Versions/v2/2.7/changesets/12432.patch target=_blank rel=external nofollow>http://www.squid-cache.org/Versions/v2/2.7/changesets/12432.patch</a>
<a href=http://www.squid-cache.org/Versions/v2/2.7/changesets/12442.patch target=_blank rel=external nofollow>http://www.squid-cache.org/Versions/v2/2.7/changesets/12442.patch</a>
Squid 3.0:
<a href=http://www.squid-cache.org/Versions/v3/3.0/changesets/b8964.patch target=_blank rel=external nofollow>http://www.squid-cache.org/Versions/v3/3.0/changesets/b8964.patch</a>
<a href=http://www.squid-cache.org/Versions/v3/3.0/changesets/b8965.patch target=_blank rel=external nofollow>http://www.squid-cache.org/Versions/v3/3.0/changesets/b8965.patch</a>
Squid 3.1:
<a href=http://www.squid-cache.org/Versions/v3/3.1/changesets/b9414.patch target=_blank rel=external nofollow>http://www.squid-cache.org/Versions/v3/3.1/changesets/b9414.patch</a>
<a href=http://www.squid-cache.org/Versions/v3/3.1/changesets/b9418.patch target=_blank rel=external nofollow>http://www.squid-cache.org/Versions/v3/3.1/changesets/b9418.patch</a>
暂无评论