_______________________________________________________________________
Package : squid
Date : August 8, 2009
Affected: 2008.1, 2009.0, 2009.1, Enterprise Server 5.0
_______________________________________________________________________
Problem Description:
Multiple vulnerabilities has been found and corrected in squid:
Due to incorrect buffer limits and related bound checks Squid is
vulnerable to a denial of service attack when processing specially
crafted requests or responses (CVE-2009-2621).
Due to incorrect data validation Squid is vulnerable to a denial
of service attack when processing specially crafted responses
(CVE-2009-2622).
This update provides fixes for these vulnerabilities.
Update:
Additional upstream security patches were applied:
Debug warnings fills up the logs.
Upstream Bug 2728: regression: assertion failed: http.cc:705: !eof
_______________________________________________________________________
References:
http://cve.mitre.org/cgi-bin/cvename.cg ... -2009-2621
http://cve.mitre.org/cgi-bin/cvename.cg ... -2009-2622
http://www.squid-cache.org/Advisories/SQUID-2009_2.txt
_______________________________________________________________________