CENTER.HU groups
CENTER.HU address

User:

Guest

www.center.hu / Archive / Security news / february, 2005 / Security update for Squid Proxy Cache 

Security update for Squid Proxy Cache

Security update for Squid Proxy Cache

Madrid, February 2, 2005 - An update has been released to fix a buffer overflow in Squid version 2.5.STABLE7 and earlier, which could be exploited to carry out Denial of Service (DoS) attacks.

This buffer overflow occurs in recvfrom() and could be exploited by an attacker to send and overlong WCCP messages which would cause the Denial of Service in the proxy and prevent users who connect to this proxy from communicating. This flaw only affects Squid servers configured to send WCCP messages to a router, according to a ´wccp_router´ directive, in the squid.conf configuration file.

Detailed information about the vulnerability, workarounds and the patches releases are available in the original advisory at: http://www.squid-cache.org/Advisories/SQUID-2005_3.txt

Oxygen3 24h-365d
by Panda Software

Back




Copyright © CENTER.HU Ltd, 2000-2010. All rights reserved

sitemap | privacy policy |

copyrights | new pages |

terms of purchase | contact us


PARTNERS: Computerworld.hu | GameStar.hu | PCWorld.hu | SG.hu | PC Guru | Hitel