LWN.net Logo

squid: insufficient bounds checking

Package(s):squid CVE #(s):CVE-2008-1612
Created:April 15, 2008 Updated:July 7, 2008
Description: From the Ubuntu advisory: It was discovered that Squid did not perform proper bounds checking when processing cache update replies. A remote authenticated user may be able to trigger an assertion error and cause a denial of service. This vulnerability is due to an incorrect fix for CVE-2007-6239.
Alerts:
Ubuntu USN-601-1 2008-04-14
Fedora FEDORA-2008-2740 2008-04-29
SuSE SUSE-SR:2008:011 2008-05-09
Mandriva MDVSA-2008:134 2007-07-04

(Log in to post comments)

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds
Powered by Rackspace Managed Hosting.