Description: | Description:
The remote host is missing updates announced in advisory RHSA-2005:766.
Squid is a full-featured Web proxy cache.
A bug was found in the way Squid displays error messages. A remote attacker could submit a request containing an invalid hostname which would result in Squid displaying a previously used error message. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2004-2479 to this issue.
Two denial of service bugs were found in the way Squid handles malformed requests. A remote attacker could submit a specially crafted request to Squid that would cause the server to crash. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the names CVE-2005-2794 and CVE-2005-2796 to these issues.
Please note that CVE-2005-2796 does not affect Red Hat Enterprise Linux 2.1
Users of Squid should upgrade to this updated package that contains backported patches, and is not vulnerable to these issues.
Solution: Please note that this update is available via Red Hat Network. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date
http://rhn.redhat.com/errata/RHSA-2005-766.html http://www.squid-cache.org/bugs/show_bug.cgi?id=1143 http://www.squid-cache.org/bugs/show_bug.cgi?id=1368 http://www.squid-cache.org/bugs/show_bug.cgi?id=1325 http://www.squid-cache.org/bugs/show_bug.cgi?id=1355
Risk factor : Medium
CVSS Score: 5.0
|