Ubuntu Forums Archive Viewer

USN-724-1: Squid vulnerability

Archived thread 1081181 from Announcements & News. Markdown source: Announcements_&_News/thread_1081181_USN-724-1_Squid_vulnerability.md

Original URL About this archive
#1

Referenced CVEs: CVE-2009-0478

Description: =========================================================== Ubuntu Security Notice USN-724-1 February 25, 2009 squid vulnerability CVE-2009-0478 =========================================================== A security issue affects the following Ubuntu releases: Ubuntu 8.10 This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu. The problem can be corrected by upgrading your system to the following package versions: Ubuntu 8.10: squid 2.7.STABLE3-1ubuntu2.1 In general, a standard system upgrade is sufficient to effect the necessary changes. Details follow: Joshua Morin, Mikko Varpiola and Jukka Taimisto discovered that Squid did not properly validate the HTTP version when processing requests. A remote attacker could exploit this to cause a denial of service (assertion failure).

More...