[RHSA-2011:1293] squid security update

Severity Moderate
Affected Packages 4
CVEs 1

Squid is a high-performance proxy caching server for web clients,
supporting FTP, Gopher, and HTTP data objects.

A buffer overflow flaw was found in the way Squid parsed replies from
remote Gopher servers. A remote user allowed to send Gopher requests to a
Squid proxy could possibly use this flaw to cause the squid child process
to crash or execute arbitrary code with the privileges of the squid user,
by making Squid perform a request to an attacker-controlled Gopher server.
(CVE-2011-3205)

Users of squid should upgrade to this updated package, which contains a
backported patch to correct this issue. After installing this update, the
squid service will be restarted automatically.

ID
RHSA-2011:1293
Severity
moderate
URL
https://access.redhat.com/errata/RHSA-2011:1293
Published
2011-09-14T00:00:00
(13 years ago)
Modified
2011-09-14T00:00:00
(13 years ago)
Rights
Copyright 2011 Red Hat, Inc.
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/redhat/squid?arch=x86_64&distro=redhat-6.1 redhat squid < 3.1.10-1.el6_1.1 redhat-6.1 x86_64
Affected pkg:rpm/redhat/squid?arch=s390x&distro=redhat-6.1 redhat squid < 3.1.10-1.el6_1.1 redhat-6.1 s390x
Affected pkg:rpm/redhat/squid?arch=ppc64&distro=redhat-6.1 redhat squid < 3.1.10-1.el6_1.1 redhat-6.1 ppc64
Affected pkg:rpm/redhat/squid?arch=i686&distro=redhat-6.1 redhat squid < 3.1.10-1.el6_1.1 redhat-6.1 i686
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...