Linux Compatible
  • News
    • Channels
    • Archive
    • Search
    • Submit
  • Articles
    • Categories
  • Knowledgebase
  • Compatibility
    • Search
  • Links
  • Forums
  • Twitter
Advertisement

Latest News
[ Windows | Linux | Apple ]

· Ubuntu 13.04 on me high-end box - Horrible
· NVIDIA GeForce Chips Comparison Table and more
· CSF 6.09 released
· Microsoft and Google agree to build YouTube app for Windows Phone 8
· OS X 10.8.4 Build 12E55 Seeded to Developers
· Wine 1.5.31 released
· Libxvmc/Libx11 Updates for Debian
· OCZ Vertex 450 SSD Reviews and more
· Proxmox VE 3.0 released
· More Windows 8.1 features discovered in WinRT?

Upcoming News
· Appointee to the Fedora Board; election nominations closing imminently.
· Logitech k310 Washable Keyboard
· [Tech ARP] BIOS Option Of The Week - Hardware Prefetcher
· SuperTooth HD VOICE Bluetooth Speakerphone Review @ TestFreaks
· A Futurelooks News Flash - An Affordable Titan – N?= VIDIA’s GEFORCE GTX 780 Reviewed
· News: AMD's A4-5000 'Kabini' APU reviewed
· Wine release 1.5.31
· NVIDIA GeForce Chips Comparison Table @ Hardware Secrets
· Resident Evil Revelations Video Review with Kaeyi Dream @ HardwareHeaven.com
· [security-announce] openSUSE-SU-2013:0825-1: important: MozillaFirefox: update to version 21.0

Linux Compatibility
· Dell Dimension 9100
· CL-CAM50001 UPC=3700284609322
· DFE 520 TX
· nVidia GeForce4 MX 440
· Gore: Ultimate Soldier
· SMC2802W V2 wi-fi 54Mbps PCI card
· Wireless modem router N300
· Dell P780
· ASUS A7V8X
· BricsCAD for Linux

New Forum Topics
· shutdown link ?
by: estirwent
on: 2013-05-11 17:46
18 replies, 6510 views

· Laptop keyboard drank soda
by: Zenn
on: 2013-04-30 00:27
1 replies, 722 views

· connecting to to internet with ubuntu
by: Zenn
on: 2013-04-30 00:26
2 replies, 4608 views

· Need Linux-compatible PS/2 expansion card
by: Zenn
on: 2013-04-30 00:26
1 replies, 796 views

· irql_not_less_or_equal blue screen
by: Zenn
on: 2013-04-30 00:25
2 replies, 1176 views

News Channels
· Drivers
· Guides
· Reviews
· Security
· Software
· Press Release
· Updates
· Interviews
· Linux
· General
· Debian
· Red Hat
· Slackware
· Gentoo
· Mandriva
· White Box
· SUSE
· GNOME
· KDE
· CentOS
· Ubuntu
· MEPIS
· Android

What's New
Login to see an overview of all news stories since your last visit.

Welcome to our website

To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.

Linux Compatible » News » January 2005 » [USN-67-1] Squid vulnerabilities

[USN-67-1] Squid vulnerabilities

Posted by Philipp Esselbach on: 01/21/2005 05:05 AM [ Print | 0 comment(s) ]

==========================================================
Ubuntu Security Notice USN-67-1 January 20, 2005
squid vulnerabilities
CAN-2005-0094, CAN-2005-0095, CAN-2005-0096, CAN-2005-0097
==========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 4.10 (Warty Warthog)

The following packages are affected:

squid

The problem can be corrected by upgrading the affected package to version 2.5.5-6ubuntu0.3. In general, a standard system upgrade is sufficient to effect the necessary changes.




Details follow:

infamous41md discovered several Denial of Service vulnerabilities in squid.

A malicious Gopher server could crash squid by sending a line bigger than 4096 bytes. (CAN-2005-0094)

If squid is configured to send WCPP (Web Cache Communication Protocol) messages to a "home router", an attacker who was able to send UDP packets with a forged source address of this router could crash the server with a specially crafted WCPP message. (CAN-2005-0095)

Previous versions of squid have a memory leak which gradually cause memory exhaustion and eventual termination. (CAN-2005-0096)

A remote attacker could crash the server by sending a specially crafted NTLM type 3 packet. (CAN-2005-0097)

Source archives:

http://security.ubuntu.com/ubuntu/pool/main/s/squid/squid_2.5.5-6ubuntu0.3.diff.gz
Size/MD5: 261632 b5eff00520a4a5ae42ea9f6848c19574
http://security.ubuntu.com/ubuntu/pool/main/s/squid/squid_2.5.5-6ubuntu0.3.dsc
Size/MD5: 652 98bccdccbd9de758502bf8fedb840605
http://security.ubuntu.com/ubuntu/pool/main/s/squid/squid_2.5.5.orig.tar.gz
Size/MD5: 1363967 6c7f3175b5fa04ab5ee68ce752e7b500

Architecture independent packages:

http://security.ubuntu.com/ubuntu/pool/main/s/squid/squid-common_2.5.5-6ubuntu0.3_all.deb
Size/MD5: 185086 b678138da7fe29c4613cb0dad17a2907

amd64 architecture (Athlon64, Opteron, EM64T Xeon)

http://security.ubuntu.com/ubuntu/pool/universe/s/squid/squid-cgi_2.5.5-6ubuntu0.3_amd64.deb
Size/MD5: 89532 0b85d26fcf6984e283c5114af77c6fd3
http://security.ubuntu.com/ubuntu/pool/main/s/squid/squid_2.5.5-6ubuntu0.3_amd64.deb
Size/MD5: 811426 d77e22c9358bcb48356bbe8d10c60119
http://security.ubuntu.com/ubuntu/pool/universe/s/squid/squidclient_2.5.5-6ubuntu0.3_amd64.deb
Size/MD5: 70860 c08aa5d1322863bae47c14890c014e52

i386 architecture (x86 compatible Intel/AMD)

http://security.ubuntu.com/ubuntu/pool/universe/s/squid/squid-cgi_2.5.5-6ubuntu0.3_i386.deb
Size/MD5: 88038 106d4406e488ee4f77148cb95e75bb5f
http://security.ubuntu.com/ubuntu/pool/main/s/squid/squid_2.5.5-6ubuntu0.3_i386.deb
Size/MD5: 726832 24384d77f74454fa88f616162008eafd
http://security.ubuntu.com/ubuntu/pool/universe/s/squid/squidclient_2.5.5-6ubuntu0.3_i386.deb
Size/MD5: 69580 985f64a429db845fbc5919ff58c00eeb

powerpc architecture (Apple Macintosh G3/G4/G5)

http://security.ubuntu.com/ubuntu/pool/universe/s/squid/squid-cgi_2.5.5-6ubuntu0.3_powerpc.deb
Size/MD5: 88972 4668dc70768e79ef115f04636c200502
http://security.ubuntu.com/ubuntu/pool/main/s/squid/squid_2.5.5-6ubuntu0.3_powerpc.deb
Size/MD5: 794288 8b93b8d27a758f52e84f783148744263
http://security.ubuntu.com/ubuntu/pool/universe/s/squid/squidclient_2.5.5-6ubuntu0.3_powerpc.deb
Size/MD5: 70358 829f568b638019de48ade7f646c134e6


Bookmark and Share

« HEXUS.article: ATI's Mobility Radeon X700 Launch · Gigabyte Geforce 6200 Review @ PCmoddingmy »

Linux Compatible » News » January 2005 » [USN-67-1] Squid vulnerabilities
All products mentioned are registered trademarks or trademarks of their respective owners.
© 2002-2013 Esselbach Internet Solutions - All Rights Reserved. Terms and privacy policy
Powered by Contentteller® Business Edition