LinuxSecurity.com
Share your story
The central voice for Linux and Open Source security news
Home News Topics Advisories HOWTOs Features Newsletters About Register

Welcome!
Sign up!
EnGarde Community
Login
Polls
What is the most important Linux security technology?
 
Advisories
Community
Linux Events
Linux User Groups
Link to Us
Security Center
Book Reviews
Security Dictionary
Security Tips
SELinux
White Papers
Featured Blogs
All About Linux
DanWalsh LiveJournal
Securitydistro
Latest Newsletters
Linux Security Week: February 6th, 2012
Linux Advisory Watch: February 3rd, 2012
Subscribe
LinuxSecurity Newsletters
E-mail:
Choose Lists:
About our Newsletters
RSS Feeds
Get the LinuxSecurity news you want faster with RSS
Powered By

  
Mandriva: squid Print E-mail
User Rating:      How can I rate this item?
Posted by Benjamin D. Thomas   
Mandrake A vulnerability have been discovered and corrected in Squid 2.x, 3.0 through 3.0.STABLE22, and 3.1 through 3.1.0.15, which allows remote attackers to cause a denial of service (assertion failure) via a crafted DNS packet that only contains a header (CVE-2010-0308). This update provides a fix to this vulnerability.
 _______________________________________________________________________

 Mandriva Linux Security Advisory                         MDVSA-2010:033
 http://www.mandriva.com/security/
 _______________________________________________________________________

 Package : squid
 Date    : February 5, 2010
 Affected: 2008.0, 2009.0, 2009.1, 2010.0, Corporate 4.0,
           Enterprise Server 5.0, Multi Network Firewall 2.0
 _______________________________________________________________________

 Problem Description:

 A vulnerability have been discovered and corrected in Squid 2.x,
 3.0 through 3.0.STABLE22, and 3.1 through 3.1.0.15, which allows
 remote attackers to cause a denial of service (assertion failure)
 via a crafted DNS packet that only contains a header (CVE-2010-0308).
 
 This update provides a fix to this vulnerability.
 _______________________________________________________________________

 References:

 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0308
 _______________________________________________________________________

 Updated Packages:

 Mandriva Linux 2008.0:
 56d1a099888684549450987984ab07e5  2008.0/i586/squid-2.6.STABLE16-1.5mdv2008.0.i586.rpm
 23ae7f244ee664020270c010d9bffc93  2008.0/i586/squid-cachemgr-2.6.STABLE16-1.5mdv2008.0.i586.rpm 
 952676e8f79dcb3cf48beb693082a055  2008.0/SRPMS/squid-2.6.STABLE16-1.5mdv2008.0.src.rpm

 Mandriva Linux 2008.0/X86_64:
 6e3757e4957a31a2c7b2c698d70a23ec  2008.0/x86_64/squid-2.6.STABLE16-1.5mdv2008.0.x86_64.rpm
 4090afb42b9c821567ef9585f72826de  2008.0/x86_64/squid-cachemgr-2.6.STABLE16-1.5mdv2008.0.x86_64.rpm 
 952676e8f79dcb3cf48beb693082a055  2008.0/SRPMS/squid-2.6.STABLE16-1.5mdv2008.0.src.rpm

 Mandriva Linux 2009.0:
 514ac3e366722bf224c6c268133c8bf5  2009.0/i586/squid-3.0-22.2mdv2009.0.i586.rpm
 af1e6999474f66abd50c0830838c37e1  2009.0/i586/squid-cachemgr-3.0-22.2mdv2009.0.i586.rpm 
 111816fac7c13dac76fc4cbb32c5d5b8  2009.0/SRPMS/squid-3.0-22.2mdv2009.0.src.rpm

 Mandriva Linux 2009.0/X86_64:
 26a88dff2af3b818c765740a226a304a  2009.0/x86_64/squid-3.0-22.2mdv2009.0.x86_64.rpm
 63f5a3ca8f76e30fd55b3d0491161b29  2009.0/x86_64/squid-cachemgr-3.0-22.2mdv2009.0.x86_64.rpm 
 111816fac7c13dac76fc4cbb32c5d5b8  2009.0/SRPMS/squid-3.0-22.2mdv2009.0.src.rpm

 Mandriva Linux 2009.1:
 ac595f8e4d801933fa14c9737f2bda2f  2009.1/i586/squid-3.0-22.2mdv2009.1.i586.rpm
 62de73c22f47725da6c437364a46e940  2009.1/i586/squid-cachemgr-3.0-22.2mdv2009.1.i586.rpm 
 c7e94a138db6a4c1388229755aee5140  2009.1/SRPMS/squid-3.0-22.2mdv2009.1.src.rpm

 Mandriva Linux 2009.1/X86_64:
 90303168b09d33f47bce7242b669a214  2009.1/x86_64/squid-3.0-22.2mdv2009.1.x86_64.rpm
 cd8aaa4a61c8ecdb5170bd9cc0d3c1f3  2009.1/x86_64/squid-cachemgr-3.0-22.2mdv2009.1.x86_64.rpm 
 c7e94a138db6a4c1388229755aee5140  2009.1/SRPMS/squid-3.0-22.2mdv2009.1.src.rpm

 Mandriva Linux 2010.0:
 eddb97e4799437f2cf0a78c6a359cb5e  2010.0/i586/squid-3.0-22.2mdv2010.0.i586.rpm
 555c13ad31b3b6aacd50bbfcb6fa9eef  2010.0/i586/squid-cachemgr-3.0-22.2mdv2010.0.i586.rpm 
 7f79b208080e8e3ead74b69e7ac840e5  2010.0/SRPMS/squid-3.0-22.2mdv2010.0.src.rpm

 Mandriva Linux 2010.0/X86_64:
 a13f8f1b479b99bdc40ddc5ad86d0be4  2010.0/x86_64/squid-3.0-22.2mdv2010.0.x86_64.rpm
 d648754975631b54d6bc992a0e39cbae  2010.0/x86_64/squid-cachemgr-3.0-22.2mdv2010.0.x86_64.rpm 
 7f79b208080e8e3ead74b69e7ac840e5  2010.0/SRPMS/squid-3.0-22.2mdv2010.0.src.rpm

 Corporate 4.0:
 0bd70b523f3e0d4d6a3b61b3e42997d1  corporate/4.0/i586/squid-2.6.STABLE1-4.7.20060mlcs4.i586.rpm
 934c278650d457d10adda359441432e2  corporate/4.0/i586/squid-cachemgr-2.6.STABLE1-4.7.20060mlcs4.i586.rpm 
 357f99500713686172ab432852f9d3c2  corporate/4.0/SRPMS/squid-2.6.STABLE1-4.7.20060mlcs4.src.rpm

 Corporate 4.0/X86_64:
 18b0b7e594cbab3d6c19a1a017b7d4b0  corporate/4.0/x86_64/squid-2.6.STABLE1-4.7.20060mlcs4.x86_64.rpm
 a22aace447ac83f960fa58fa7e8a1329  corporate/4.0/x86_64/squid-cachemgr-2.6.STABLE1-4.7.20060mlcs4.x86_64.rpm 
 357f99500713686172ab432852f9d3c2  corporate/4.0/SRPMS/squid-2.6.STABLE1-4.7.20060mlcs4.src.rpm

 Mandriva Enterprise Server 5:
 0672692de71c27f8f39e9908b3738c41  mes5/i586/squid-3.0-22.2mdvmes5.i586.rpm
 369ada9958ee2314f05c521ebcfdf538  mes5/i586/squid-cachemgr-3.0-22.2mdvmes5.i586.rpm 
 c016e10f40be982e8721bd25d7cbde2b  mes5/SRPMS/squid-3.0-22.2mdvmes5.src.rpm

 Mandriva Enterprise Server 5/X86_64:
 ed47df165089fab968431ca1530e609e  mes5/x86_64/squid-3.0-22.2mdvmes5.x86_64.rpm
 52c1eefa1b67c95d50ade95e2b37b4ae  mes5/x86_64/squid-cachemgr-3.0-22.2mdvmes5.x86_64.rpm 
 c016e10f40be982e8721bd25d7cbde2b  mes5/SRPMS/squid-3.0-22.2mdvmes5.src.rpm

 Multi Network Firewall 2.0:
 e42b3292a67b734d582f565ffb7376ce  mnf/2.0/i586/squid-2.5.STABLE9-1.11.M20mdk.i586.rpm 
 288d79b7fa0bdf3e3c3ae17b65a661ac  mnf/2.0/SRPMS/squid-2.5.STABLE9-1.11.M20mdk.src.rpm
 _______________________________________________________________________

 To upgrade automatically use MandrivaUpdate or urpmi.  The verification
 of md5 checksums and GPG signatures is performed automatically for you.

 All packages are signed by Mandriva for security.  You can obtain the
 GPG public key of the Mandriva Security Team by executing:

  gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

 You can view other update advisories for Mandriva Linux at:

  http://www.mandriva.com/security/advisories

 If you want to report vulnerabilities, please contact

  security_(at)_mandriva.com
 _______________________________________________________________________

 Type Bits/KeyID     Date       User ID
 pub  1024D/22458A98 2000-07-10 Mandriva Security Team
  
 
< Prev   Next >
    
Partner

 

Latest Features
Password guessing with Medusa 2.0
Password guessing as an attack vector
Squid and Digest Authentication
Squid and Basic Authentication
Demystifying the Chinese Hacking Industry: Earning 6 Million a Night
Free Online security course (LearnSIA) - A Call for Help
What You Need to Know About Linux Rootkits
Review: A Practical Guide to Fedora and Red Hat Enterprise Linux - Fifth Edition
Using the sec-wall Security Proxy
sec-wall: Open Source Security Proxy
Yesterday's Edition
Operation Ghost Click DNS servers to shut down in March
Partner Sponsor

Community | HOWTOs | Blogs | Features | Book Reviews | Networking
 Security Projects |  Latest News |  Newsletters |  SELinux |  Privacy |  Home
 Hardening |   About Us |   Advertise |   Legal Notice |   RSS |   Guardian Digital
(c)Copyright 2012 Guardian Digital, Inc. All rights reserved.