LWN.net Logo

squid: denial of service

Package(s):squid CVE #(s):CVE-2012-5643
Created:December 26, 2012 Updated:March 11, 2013
Description: From the CVE entry:

Multiple memory leaks in tools/cachemgr.cc in cachemgr.cgi in Squid 2.x and 3.x before 3.1.22, 3.2.x before 3.2.4, and 3.3.x before 3.3.0.2 allow remote attackers to cause a denial of service (memory consumption) via (1) invalid Content-Length headers, (2) long POST requests, or (3) crafted authentication credentials.

Alerts:
Fedora FEDORA-2012-20537 2012-12-26
Mageia MGASA-2012-0368 2012-12-27
openSUSE openSUSE-SU-2013:0162-1 2013-01-23
openSUSE openSUSE-SU-2013:0186-1 2013-01-23
Ubuntu USN-1713-1 2013-01-30
Fedora FEDORA-2013-1616 2013-02-08
Fedora FEDORA-2013-1625 2013-02-08
Mandriva MDVSA-2013:013 2013-02-20
Red Hat RHSA-2013:0505-02 2013-02-21
Debian DSA-2631-1 2013-02-24
Oracle ELSA-2013-0505 2013-02-25
Scientific Linux SL-squi-20130228 2013-02-28
CentOS CESA-2013:0505 2013-03-09

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds