Debian: New squid packages fix several vulnerabilities
Posted by Benjamin D. Thomas   
Debian Update package.
- --------------------------------------------------------------------------
Debian Security Advisory DSA 809-1                                        Martin Schulze
September 13th, 2005          
- --------------------------------------------------------------------------

Package        : squid
Vulnerability  : several
Problem type   : remote
Debian-specific: no
CVE ID         : CAN-2005-2794 CAN-2005-2796

Several vulnerabilities have been discovered in Squid, the popular WWW
proxy cache.  The Common Vulnerabilities and Exposures project
identifies the following problems:


    Certain aborted requests that trigger an assert may allow remote
    attackers to cause a denial of service.


    Specially crafted requests can cause a denial of service.

For the stable distribution (sarge) these problems have been fixed in
version 2.5.9-10sarge1.

For the unstable distribution (sid) these problems have been fixed in
version 2.5.10-5.

We recommend that you upgrade your squid package.

