Package name
squid
Date
2004-10-21
Advisory ID
MDKSA-2004:112
Affected versions
9.2 amd64 , CS2.1 x86_64 , 10.0 amd64 , 10.1 i586 , 10.0 i586 , 9.2 i586 , MNF8.2 i586 , CS2.1 i586 , 10.1 x86_64

Problem description

iDEFENSE discovered a Denial of Service vulnerability in squid version 2.5.STABLE6 and previous. The problem is due to an ASN1 parsing error where certain header length combinations can slip through the validations performed by the ASN1 parser, leading to the server assuming there is heap corruption or some other exceptional condition, and closing all current connections then restarting. Squid 2.5.STABLE7 has been released to address this issue; the provided packages are patched to fix the issue.

Updated packages

9.2 amd64

 52a4d17751414ac7a5f3c091ef4b1c48  amd64/9.2/RPMS/squid-2.5.STABLE3-3.4.92mdk.amd64.rpm
a09fa332b5f211305012012ca24e59d2  amd64/9.2/SRPMS/squid-2.5.STABLE3-3.4.92mdk.src.rpm

CS2.1 x86_64

 4ba0032bb54a30c1d2cb221b128f9f22  x86_64/corporate/2.1/RPMS/squid-2.4.STABLE7-2.2.C21mdk.x86_64.rpm
ad5d5630905720f6e2b358430d5d366a  x86_64/corporate/2.1/SRPMS/squid-2.4.STABLE7-2.2.C21mdk.src.rpm

10.0 amd64

 197673fc1350ee72516f28a1bced5125  amd64/10.0/RPMS/squid-2.5.STABLE4-2.2.100mdk.amd64.rpm
6c927aa442c77b743f7861b05930cf9d  amd64/10.0/SRPMS/squid-2.5.STABLE4-2.2.100mdk.src.rpm

10.1 i586

 dd7c5ea7eb80463d17240e0cbaa5daf6  10.1/RPMS/squid-2.5.STABLE6-2.1.101mdk.i586.rpm
be8bb54e123a25d2a0b5c777bfe145d5  10.1/SRPMS/squid-2.5.STABLE6-2.1.101mdk.src.rpm

10.0 i586

 73fa6afb48cd0c9985ff1ca0fe4502e6  10.0/RPMS/squid-2.5.STABLE4-2.2.100mdk.i586.rpm
6c927aa442c77b743f7861b05930cf9d  10.0/SRPMS/squid-2.5.STABLE4-2.2.100mdk.src.rpm

9.2 i586

 a026dc8229fddb9072b9029f2cf9c0e9  9.2/RPMS/squid-2.5.STABLE3-3.4.92mdk.i586.rpm
a09fa332b5f211305012012ca24e59d2  9.2/SRPMS/squid-2.5.STABLE3-3.4.92mdk.src.rpm

MNF8.2 i586

 95fc106c9cd480a933b4aefab1ab2ae8  mnf8.2/RPMS/squid-2.4.STABLE7-1.3.M82mdk.i586.rpm
0895cefcfe0e7bb183502a19c37b4814  mnf8.2/SRPMS/squid-2.4.STABLE7-1.3.M82mdk.src.rpm

CS2.1 i586

 d430ee037aea1e66b1bcc488e2e502ca  corporate/2.1/RPMS/squid-2.4.STABLE7-2.2.C21mdk.i586.rpm
ad5d5630905720f6e2b358430d5d366a  corporate/2.1/SRPMS/squid-2.4.STABLE7-2.2.C21mdk.src.rpm

10.1 x86_64

 2dedd75cb87b7a101db6556e234dbf72  x86_64/10.1/RPMS/squid-2.5.STABLE6-2.1.101mdk.x86_64.rpm
be8bb54e123a25d2a0b5c777bfe145d5  x86_64/10.1/SRPMS/squid-2.5.STABLE6-2.1.101mdk.src.rpm

References