Security Advisory New squid packages available

Advisory: RHSA-2002:029-11
Type: Security Advisory
Severity: N/A
Issued on: 2002-02-19
Last updated on: 2002-03-14
Affected Products: Red Hat Linux 6.2
Red Hat Linux 7.0
Red Hat Linux 7.1
Red Hat Linux 7.2
OVAL: N/A
CVEs (cve.mitre.org): CVE-2002-0067
CVE-2002-0068
CVE-2002-0069

Details

New squid packages are available that fix various vulnerabilities. Some of
these vulnerabilities could be used to perform a denial of service (DoS)
attack or allow remote users to execute code as the user squid.

Squid is a high-performance proxy caching server. Various security issues
have been found in Squid up to and including version 2.4.STABLE2. These were:

- a memory leak in the SNMP code
- a crash on specially-formatted data in FTP URL parsing
- HTCP would still be active, even if it was disabled in the config file

These errata pacakges contain Squid version 2.4.STABLE3, which is not
vulnerable to these issues. It is recommended that all users of Squid
update to the fixed packages.

Note: SNMP support is disabled in the
default configuration of these packages (it was previously enabled).
If you need SNMP support, edit your squid configuration and change
the 'snmp_port' option; the default port for SNMP enabled-squid is
3401.

Thanks go to Jouko Pynnonen for notifying us of the FTP vulnerability and
to the Squid team for providing patches.

The Common Vulnerabilities and Exposures project (cve.mitre.org) has
assigned the names CAN-2002-0067, CAN-2002-0068, CAN-2002-0069 to these issues.


Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

To update all RPMs for your particular architecture, run:

rpm -Fvh [filenames]

where [filenames] is a list of the RPMs you wish to upgrade. Only those
RPMs which are currently installed will be updated. Those RPMs which are
not installed but included in the list will not be updated. Note that you
can also use wildcards (*.rpm) if your current directory *only* contains
the
desired RPMs.

Please note that this update is also available via Red Hat Network. Many
people find this an easier way to apply updates. To use Red Hat Network,
launch the Red Hat Update Agent with the following command:

up2date

This will start an interactive process that will result in the appropriate
RPMs being upgraded on your system.

Updated packages

Red Hat Linux 6.2

SRPMS:
squid-2.4.STABLE3-1.6.2.src.rpm
File outdated by:  RHSA-2002:051
    b3d4d0c9e53b01c19f700df9ce17d0e5
 
Alpha:
squid-2.4.STABLE3-1.6.2.alpha.rpm
File outdated by:  RHSA-2002:051
    17ef449e9a97d10cdbc3d120fdb50f2c
 
IA-32:
squid-2.4.STABLE3-1.6.2.i386.rpm
File outdated by:  RHSA-2002:051
    c84cd128b04cb373fe32d7b2288db841
 
Sparc:
squid-2.4.STABLE3-1.6.2.sparc.rpm
File outdated by:  RHSA-2002:051
    9264d770d126b5b33cf9dd428bf1db14
 
Red Hat Linux 7.0

SRPMS:
squid-2.4.STABLE3-1.7.0.src.rpm
File outdated by:  RHSA-2002:051
    21dfdf2375a15cddcc51a2aaec7ca651
 
Alpha:
squid-2.4.STABLE3-1.7.0.alpha.rpm
File outdated by:  RHSA-2002:051
    40996e76071a5d4680a1d90335dd87e2
 
IA-32:
squid-2.4.STABLE3-1.7.0.i386.rpm
File outdated by:  RHSA-2002:051
    0417cdb61da2d5d28da0d995976dce1d
 
Red Hat Linux 7.1

SRPMS:
squid-2.4.STABLE3-1.7.1.src.rpm
File outdated by:  RHSA-2002:051
    953d1e9e04b2a9efb94e4e74a99167a3
 
Alpha:
squid-2.4.STABLE3-1.7.1.alpha.rpm
File outdated by:  RHSA-2002:051
    61ad76cb69e47540ffe127b7dff99e5a
 
IA-32:
squid-2.4.STABLE3-1.7.1.i386.rpm
File outdated by:  RHSA-2002:051
    7061c04ab2a0e97a284ced5a98bd2877
 
IA-64:
squid-2.4.STABLE3-1.7.1.ia64.rpm
File outdated by:  RHSA-2002:051
    ae562f0cc3db33cfb6c1a64612aa26bb
 
Red Hat Linux 7.2

SRPMS:
squid-2.4.STABLE3-1.7.2.src.rpm
File outdated by:  RHSA-2002:051
    72d271f03bf9fee7dc9ba2d4f94269d4
 
IA-32:
squid-2.4.STABLE3-1.7.2.i386.rpm
File outdated by:  RHSA-2002:051
    0f8a1132399b4f149426c34f9203030f
 
IA-64:
squid-2.4.STABLE3-1.7.2.ia64.rpm
File outdated by:  RHSA-2002:051
    bdaa724f704c4f0f0530a19dd7081cac
 
s390:
ftp://updates.redhat.com/7.2/en/os/s390/squid-2.4.STABLE3-1.7.2.s390.rpm
Missing file
    c81860b2bb0a472c978a94448aa97382
 

References


Keywords

ftp, htcp, snmp, squid


These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/