[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

RHSA-2011:0545-01 -- Redhat squid

ID: oval:org.secpod.oval:def:500111Date: (C)2012-01-31   (M)2021-07-09
Class: PATCHFamily: unix




Squid is a high-performance proxy caching server for web clients, supporting FTP, Gopher, and HTTP data objects. It was found that string comparison functions in Squid did not properly handle the comparisons of NULL and empty strings. A remote, trusted web client could use this flaw to cause the squid daemon to crash via a specially-crafted request. This update also fixes the following bugs: * A small memory leak in Squid caused multiple "ctx: enter level" messages to be logged to "/var/log/squid/cache.log". This update resolves the memory leak. * This erratum upgrades Squid to upstream version 3.1.10. This upgraded version supports the Google Instant service and introduces various code improvements. Users of squid should upgrade to this updated package, which resolves these issues. After installing this update, the squid service will be restarted automatically.

Platform:
Red Hat Enterprise Linux 6
Product:
squid
Reference:
RHSA-2011:0545-01
CVE-2010-3072
CVE    1
CVE-2010-3072
CPE    57
cpe:/a:squid-cache:squid:3.0.stable19
cpe:/a:squid-cache:squid:3.0.stable18
cpe:/a:squid-cache:squid:3.0.stable15
cpe:/a:squid-cache:squid:3.0.stable14
...

© SecPod Technologies