Package name
squid
Date
2002-02-26
Advisory ID
MDKSA-2002:016-1
Affected versions
SNF7.2 i586 , CS1.0 i586 , 8.0 i586 , 8.0 i586 , 7.1 i586 , 7.2 i586

Problem description

Three security issues were found in the 2.x versions of the Squid proxy server up to and including 2.4.STABLE3. The first is a memory leak in the optional SNMP interface to Squid which could allow a malicious user who can send packets to the Squid SNMP port to possibly perform a Denial of Service attack on ther server if the SNMP interface is enabled. The next is a buffer overflow in the implementation of ftp:// URLs where allowed users could possibly perform a DoS on the server, and may be able to trigger remote execution of code (which the authors have not yet confirmed). The final issue is with the HTCP interface which cannot be properly disabled from squid.conf; HTCP is enabled by default on Mandrake Linux systems. Update: The squid updates for all versions other than Mandrake Linux were incorrectly built with LDAP authentication which introduced a dependency on OpenLDAP. These new packages do not use LDAP authentication. The Single Network Firewall 7.2 package previously released did not use LDAP authentication, however rebuilding the source RPM package required LDAP to be installed. Single Network Firewall 7.2 users do not need to upgrade to these packages to have a properly function squid.

Updated packages

SNF7.2 i586

 0c3cfdf038650a8c85e703c8859df8d7  snf7.2/RPMS/squid-2.4.STABLE4-1.5mdk.i586.rpm
a46c4bf51883fcfee529de2812f55458  snf7.2/SRPMS/squid-2.4.STABLE4-1.5mdk.src.rpm

CS1.0 i586

 60bb70afa95f2b43727bc8c9794fb0f9  1.0.1/RPMS/squid-2.4.STABLE4-1.5mdk.i586.rpm
a46c4bf51883fcfee529de2812f55458  1.0.1/SRPMS/squid-2.4.STABLE4-1.5mdk.src.rpm

8.0 i586

 174eaf577cfde553ee0b8eb301792cba  8.0/RPMS/squid-2.4.STABLE4-1.6mdk.i586.rpm
e1d0df4fe930669e3ba12b90caefeca3  8.0/SRPMS/squid-2.4.STABLE4-1.6mdk.src.rpm

8.0 i586

 375ecbfec5947e9f47be3ada5084fc88  ppc/8.0/RPMS/squid-2.4.STABLE4-1.6mdk.ppc.rpm
e1d0df4fe930669e3ba12b90caefeca3  ppc/8.0/SRPMS/squid-2.4.STABLE4-1.6mdk.src.rpm

7.1 i586

 60bb70afa95f2b43727bc8c9794fb0f9  7.1/RPMS/squid-2.4.STABLE4-1.5mdk.i586.rpm
a46c4bf51883fcfee529de2812f55458  7.1/SRPMS/squid-2.4.STABLE4-1.5mdk.src.rpm

7.2 i586

 0c3cfdf038650a8c85e703c8859df8d7  7.2/RPMS/squid-2.4.STABLE4-1.5mdk.i586.rpm
a46c4bf51883fcfee529de2812f55458  7.2/SRPMS/squid-2.4.STABLE4-1.5mdk.src.rpm

References