Madrid, February 2, 2005 - An update has been released to fix a buffer overflow in Squid version 2.5.STABLE7 and earlier, which could be exploited to carry out Denial of Service (DoS) attacks.
This buffer overflow occurs in recvfrom() and could be exploited by an attacker to send and overlong WCCP messages which would cause the Denial of Service in the proxy and prevent users who connect to this proxy from communicating. This flaw only affects Squid servers configured to send WCCP messages to a router, according to a ´wccp_router´ directive, in the squid.conf configuration file.
Detailed information about the vulnerability, workarounds and the patches releases are available in the original advisory at: http://www.squid-cache.org/Advisories/SQUID-2005_3.txt
Oxygen3 24h-365d
by Panda Software
Member of IVSZ

Member of SZEK

Acer Affinity Gold partner

Dell Registered Partner
![]()
OKI System Shinrai Partner

XEROX Viszonteladó

APC megbízható szállító

EATON Authorized Partner

Cisco partner

Symantec Software Partner

ESET Partner
![]()
FUJITSU partner

LENOVO Premium Partner

IBM Business Partner

PARTNERS: Computerworld.hu | GameStar.hu | PCWorld.hu | SG.hu | PC Guru | Hitel