Fedora alert FEDORA-2009-8327 (squid)
| From: | updates@fedoraproject.org | |
| To: | fedora-package-announce@redhat.com | |
| Subject: | [SECURITY] Fedora 10 Update: squid-3.0.STABLE18-1.fc10 | |
| Date: | Mon, 17 Aug 2009 21:59:33 +0000 | |
| Message-ID: | <20090817215933.5910210F897@bastion2.fedora.phx.redhat.com> | |
| Archive‑link: | Article |
-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2009-8327 2009-08-07 04:36:00 -------------------------------------------------------------------------------- Name : squid Product : Fedora 10 Version : 3.0.STABLE18 Release : 1.fc10 URL : http://www.squid-cache.org Summary : The Squid proxy caching server Description : Squid is a high-performance proxy caching server for Web clients, supporting FTP, gopher, and HTTP data objects. Unlike traditional caching software, Squid handles all requests in a single, non-blocking, I/O-driven process. Squid keeps meta data and especially hot objects cached in RAM, caches DNS lookups, supports non-blocking DNS lookups, and implements negative caching of failed requests. Squid consists of a main server program squid, a Domain Name System lookup program (dnsserver), a program for retrieving FTP data (ftpget), and some management and client tools. -------------------------------------------------------------------------------- Update Information: Fixes several denial of service issues which could allow an attacker to stop the Squid service. CVE-2009-2621, CVE-2009-2622 -------------------------------------------------------------------------------- ChangeLog: * Tue Aug 4 2009 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.0.STABLE18-1 - Update to 3.0.STABLE18 * Sat Aug 1 2009 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.0.STABLE17-3 - Squid Bug #2728: regression: assertion failed: http.cc:705: "!eof" * Mon Jul 27 2009 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.0.STABLE17-1 - Bug #514014, update to 3.0.STABLE17 fixing the denial of service issues mentioned in Squid security advisory SQUID-2009_2. * Mon Jul 13 2009 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.0.STABLE16-2 - Upgrade to latest upstream * Sat May 23 2009 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.0.STABLE15-2 - Upgrade to 3.0.STABLE15 - Bug #453304 - Squid requires restart after Network Manager connection setup * Mon Apr 20 2009 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.0.STABLE14-1 - upgrade to latest upstream * Thu Feb 5 2009 Jonathan Steffan <jsteffan@fedoraproject.org> - 7:3.0.STABLE13-1 - upgrade to latest upstream * Thu Jan 29 2009 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.0.STABLE12-1 - upgrade to latest upstream * Fri Dec 19 2008 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.0.STABLE10-3 - actually include the upstream bugfixes in the build * Fri Dec 19 2008 Henrik Nordstrom <henrik@henriknordstrom.net> - 7:3.0.STABLE10-2 - upstream bugfixes for cache corruption and access.log response size errors -------------------------------------------------------------------------------- References: [ 1 ] Bug #514013 - CVE-2009-2621, CVE-2009-2622 squid: multiple vulnerabilities fixed in squid 3.0.STABLE17 https://bugzilla.redhat.com/show_bug.cgi?id=514013 -------------------------------------------------------------------------------- This update can be installed with the "yum" update program. Use su -c 'yum update squid' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/. All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at http://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ Fedora-package-announce mailing list Fedora-package-announce@redhat.com http://www.redhat.com/mailman/listinfo/fedora-package-ann...
