LWN.net Logo

squid: insufficient bounds checking

Package(s):squid CVE #(s):CVE-2008-1612
Created:April 15, 2008 Updated:March 25, 2009
Description: From the Ubuntu advisory: It was discovered that Squid did not perform proper bounds checking when processing cache update replies. A remote authenticated user may be able to trigger an assertion error and cause a denial of service. This vulnerability is due to an incorrect fix for CVE-2007-6239.
Alerts:
Gentoo 200903-38 2009-03-24
Debian DSA-1646-2 2008-10-11
Debian DSA-1646-1 2008-10-07
Mandriva MDVSA-2008:134 2007-07-04
SuSE SUSE-SR:2008:011 2008-05-09
Fedora FEDORA-2008-2740 2008-04-29
Ubuntu USN-601-1 2008-04-14

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds