Description: | Description: The remote host is missing updates announced in advisory RHSA-2010:0221.
Squid is a high-performance proxy caching server for web clients, supporting FTP, Gopher, and HTTP data objects.
A flaw was found in the way Squid processed certain external ACL helper HTTP header fields that contained a delimiter that was not a comma. A remote attacker could issue a crafted request to the Squid server, causing excessive CPU use (up to 100%). (CVE-2009-2855)
Note: The CVE-2009-2855 issue only affected non-default configurations that use an external ACL helper script.
A flaw was found in the way Squid handled truncated DNS replies. A remote attacker able to send specially-crafted UDP packets to Squid's DNS client port could trigger an assertion failure in Squid's child process, causing that child process to exit. (CVE-2010-0308)
Solution: All users of squid should upgrade to this updated package, which resolves these issues. After installing this update, the squid service will be restarted automatically.
Please note that this update is available via Red Hat Network. To use Red Hat Network, launch the Red Hat Update Agent with the following command: up2date
http://rhn.redhat.com/errata/RHSA-2010-0221.html http://www.redhat.com/security/updates/classification/#low
Risk factor : Medium
CVSS Score: 5.0
|