Security Advisory squid security update

Advisory: RHSA-2004:591-04
Type: Security Advisory
Severity: Important
Issued on: 2004-10-20
Last updated on: 2004-10-20
Affected Products: Red Hat Desktop (v. 3)
Red Hat Enterprise Linux AS (v. 2.1)
Red Hat Enterprise Linux AS (v. 3)
Red Hat Enterprise Linux ES (v. 2.1)
Red Hat Enterprise Linux ES (v. 3)
Red Hat Enterprise Linux WS (v. 3)
Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor
OVAL: N/A
CVEs (cve.mitre.org): CVE-2004-0918

Details

An updated squid package that fixes a remote denial of service vulnerability
is now avaliable.

Squid is a full-featured Web proxy cache.

iDEFENSE reported a flaw in the squid SNMP module. This flaw could allow
an attacker who has the ability to send arbitrary packets to the SNMP port
to restart the server, causing it to drop all open connections. The Common
Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name
CAN-2004-0918 to this issue.

All users of squid should update to this erratum package, which contains a
backport of the security fix for this vulnerability.


Solution

Before applying this update, make sure that all previously-released
errata relevant to your system have been applied. Use Red Hat
Network to download and update your packages. To launch the Red Hat
Update Agent, use the following command:

up2date

For information on how to install packages manually, refer to the
following Web page for the System Administration or Customization
guide specific to your system:

http://www.redhat.com/docs/manuals/enterprise/

Updated packages

Red Hat Desktop (v. 3)

SRPMS:
squid-2.5.STABLE3-6.3E.2.src.rpm
File outdated by:  RHSA-2008:0214
    919b9823a67f83efafc8e34dd7b54a76
 
IA-32:
squid-2.5.STABLE3-6.3E.2.i386.rpm
File outdated by:  RHSA-2008:0214
    1e97031b4ab8ed0095aed15fc8023f57
 
x86_64:
squid-2.5.STABLE3-6.3E.2.x86_64.rpm
File outdated by:  RHSA-2008:0214
    50f854496bd475854ef578891dc5d630
 
Red Hat Enterprise Linux AS (v. 2.1)

SRPMS:
squid-2.4.STABLE7-1.21as.src.rpm
File outdated by:  RHSA-2008:0214
    d6f19557d67672e3f08e2ef191c74ba2
 
IA-32:
squid-2.4.STABLE7-1.21as.i386.rpm
File outdated by:  RHSA-2008:0214
    656bb40dacbfda418bc5b0b0a2afb9ca
 
IA-64:
squid-2.4.STABLE7-1.21as.ia64.rpm
File outdated by:  RHSA-2008:0214
    4c7f9233d5c07161815cd0f238598ad9
 
Red Hat Enterprise Linux AS (v. 3)

SRPMS:
squid-2.5.STABLE3-6.3E.2.src.rpm
File outdated by:  RHSA-2008:0214
    919b9823a67f83efafc8e34dd7b54a76
 
IA-32:
squid-2.5.STABLE3-6.3E.2.i386.rpm
File outdated by:  RHSA-2008:0214
    1e97031b4ab8ed0095aed15fc8023f57
 
IA-64:
squid-2.5.STABLE3-6.3E.2.ia64.rpm
File outdated by:  RHSA-2008:0214
    b47592e7fc983dcef36e7949bc603014
 
PPC:
squid-2.5.STABLE3-6.3E.2.ppc.rpm
File outdated by:  RHSA-2008:0214
    73cc5efea1bad51e51858f2e56ea1581
 
s390:
squid-2.5.STABLE3-6.3E.2.s390.rpm
File outdated by:  RHSA-2008:0214
    d42bd6385028a6336b62acd9e1d3b551
 
s390x:
squid-2.5.STABLE3-6.3E.2.s390x.rpm
File outdated by:  RHSA-2008:0214
    c9cbce5de6662b4cc156dce76829bfe1
 
x86_64:
squid-2.5.STABLE3-6.3E.2.x86_64.rpm
File outdated by:  RHSA-2008:0214
    50f854496bd475854ef578891dc5d630
 
Red Hat Enterprise Linux ES (v. 2.1)

SRPMS:
squid-2.4.STABLE7-1.21as.src.rpm
File outdated by:  RHSA-2008:0214
    d6f19557d67672e3f08e2ef191c74ba2
 
IA-32:
squid-2.4.STABLE7-1.21as.i386.rpm
File outdated by:  RHSA-2008:0214
    656bb40dacbfda418bc5b0b0a2afb9ca
 
Red Hat Enterprise Linux ES (v. 3)

SRPMS:
squid-2.5.STABLE3-6.3E.2.src.rpm
File outdated by:  RHSA-2008:0214
    919b9823a67f83efafc8e34dd7b54a76
 
IA-32:
squid-2.5.STABLE3-6.3E.2.i386.rpm
File outdated by:  RHSA-2008:0214
    1e97031b4ab8ed0095aed15fc8023f57
 
IA-64:
squid-2.5.STABLE3-6.3E.2.ia64.rpm
File outdated by:  RHSA-2008:0214
    b47592e7fc983dcef36e7949bc603014
 
x86_64:
squid-2.5.STABLE3-6.3E.2.x86_64.rpm
File outdated by:  RHSA-2008:0214
    50f854496bd475854ef578891dc5d630
 
Red Hat Enterprise Linux WS (v. 3)

SRPMS:
squid-2.5.STABLE3-6.3E.2.src.rpm
File outdated by:  RHSA-2008:0214
    919b9823a67f83efafc8e34dd7b54a76
 
IA-32:
squid-2.5.STABLE3-6.3E.2.i386.rpm
File outdated by:  RHSA-2008:0214
    1e97031b4ab8ed0095aed15fc8023f57
 
IA-64:
squid-2.5.STABLE3-6.3E.2.ia64.rpm
File outdated by:  RHSA-2008:0214
    b47592e7fc983dcef36e7949bc603014
 
x86_64:
squid-2.5.STABLE3-6.3E.2.x86_64.rpm
File outdated by:  RHSA-2008:0214
    50f854496bd475854ef578891dc5d630
 
Red Hat Linux Advanced Workstation 2.1 for the Itanium Processor

SRPMS:
squid-2.4.STABLE7-1.21as.src.rpm
File outdated by:  RHSA-2008:0214
    d6f19557d67672e3f08e2ef191c74ba2
 
IA-64:
squid-2.4.STABLE7-1.21as.ia64.rpm
File outdated by:  RHSA-2008:0214
    4c7f9233d5c07161815cd0f238598ad9
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

135319 - CAN-2004-0918 SNMP DoS


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/