Squid: Multiple vulnerabilities
1.
Gentoo Linux Security Advisory
Version Information
| Advisory Reference |
GLSA 201110-24 / Squid |
| Release Date |
October 26, 2011 |
| Latest Revision |
October 26, 2011: 1 |
| Impact |
high |
| Exploitable |
remote |
| Package |
Vulnerable versions |
Unaffected versions |
Architecture(s) |
| net-proxy/squid |
<
3.1.15 |
>=
3.1.15 |
All supported architectures
|
Related bugreports:
#279379, #279380, #301828, #334263, #381065, #386215
Synopsis
Multiple vulnerabilities were found in Squid allowing attackers to
execute arbitrary code or cause a Denial of Service.
2.
Impact Information
Background
Squid is a full-featured web proxy cache.
Description
Multiple vulnerabilities have been discovered in Squid. Please review
the CVE identifiers referenced below for details.
Impact
Remote unauthenticated attackers may be able to execute arbitrary code
with the privileges of the Squid process or cause a Denial of Service.
3.
Resolution Information
Workaround
There is no known workaround at this time.
Resolution
All squid users should upgrade to the latest version:
Code Listing 3.1: Resolution |
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-proxy/squid-3.1.15"
|
NOTE: This is a legacy GLSA. Updates for all affected architectures are
available since September 4, 2011. It is likely that your system is
already no longer affected by this issue.
4.
References
|