- Issued:
- 2015-07-22
- Updated:
- 2015-07-22
RHBA-2015:1314 - Bug Fix Advisory
Synopsis
squid bug fix and enhancement update
Type/Severity
Bug Fix Advisory
Red Hat Insights patch analysis
Identify and remediate systems affected by this advisory.
Topic
Updated squid packages that fix several bugs and add various enhancements are
now available for Red Hat Enterprise Linux 6.
Description
Squid is a high-performance proxy caching server for web clients, supporting
FTP, Gopher, and HTTP data objects.
The squid packages have been upgraded to upstream version 3.1.23, which provides
a number of bug fixes and enhancements over the previous version. Among others,
this update adds support for the HTTP/1.1 POST and PUT responses with no message
body to squid. (BZ#999305)
This update also fixes the following bugs:
- During the testing phase, it was discovered that restarting squid caused all
files on the system to be deleted. Red Hat has fixed the bug before it could
affect any users of squid. As a result, restarting squid does not cause any
files on the system to be deleted. This bug was never released neither as part
of Red Hat Enterprise Linux, nor as part of any upstream version of the squid
packages. For more information about the bug, see the Knowledgebase Solution
linked to in the References section. (BZ#1202858)
- Prior to this update, it was possible to start a new instance of squid while a
previous instance was still running. Consequently, the previous instance of
squid was running simultaneously with the new instance. This update modifies the
squid init script to verify that squid has been terminated before starting a new
instance. As a result, the squid init script fails with an error when a new
instance is initiated in this scenario, allowing the administrator to properly
handle the situation. (BZ#1102343)
- Under high system load, the squid process sometimes terminated unexpectedly
with a segmentation fault during reboot. This update provides better memory
handling during reboot, thus fixing this bug. (BZ#1112842)
- Previously, squid sometimes returned an incorrect tag from the Access Control
List (ACL) code when using an external ACL. The bug has been fixed, and squid no
longer returns the incorrect ACL tag in this situation. (BZ#1114714)
- Prior to this update, squid in some cases terminated unexpectedly with the
following error message:
xstrdup: tried to dup a NULL pointer!
This update fixes the incorrect error handling that caused this problem. As a
result, the described error no longer causes squid to crash. (BZ#1149588)
- Previously, certain monitoring utilities could not load the Management
Information Base (MIB) modules. The obsolete MIB file causing this problem has
been updated, and the MIB modules can now be loaded as expected. (BZ#1162115)
- Previously, it was not possible to log host names. With this update, squid no
longer sends malformed DNS PTR queries, and as a result, host names are logged
as expected. (BZ#1165618)
- Prior to this update, squid terminated unexpectedly when it encountered a
certain assertion in the squid code. The assertion has been replaced with proper
error handling, and squid now handles the described situation gracefully.
(BZ#1171967)
- Previously, squid exceeded the limit of maximum locks set to 65,535 under
certain circumstances. Consequently, squid terminated unexpectedly. This update
significantly increases the lock limit. The new limit is sufficient to prevent
squid from exceeding the maximum limit of locks in usual situations.
(BZ#1177413)
In addition, this update adds the following enhancement:
- The squid packages are now built with the "--enable-http-violations" option
and allow the user to hide or rewrite HTTP headers. (BZ#1171947)
Users of squid are advised to upgrade to these updated packages, which fix these
bugs and add these enhancements. After installing this update, the squid service
will be restarted automatically.
Solution
Before applying this update, make sure all previously released errata relevant
to your system have been applied.
For details on how to apply this update, refer to:
Affected Products
- Red Hat Enterprise Linux Server 6 x86_64
- Red Hat Enterprise Linux Server 6 i386
- Red Hat Enterprise Linux Server - Extended Life Cycle Support 6 i386
- Red Hat Enterprise Linux Workstation 6 x86_64
- Red Hat Enterprise Linux Workstation 6 i386
- Red Hat Enterprise Linux for IBM z Systems 6 s390x
- Red Hat Enterprise Linux for Power, big endian 6 ppc64
- Red Hat Enterprise Linux Server from RHUI 6 x86_64
- Red Hat Enterprise Linux Server from RHUI 6 i386
- Red Hat Enterprise Linux Server - Extended Life Cycle Support 6 x86_64
- Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 6 s390x
- Red Hat Enterprise Linux Server - Extended Life Cycle Support Extension 6 x86_64
- Red Hat Enterprise Linux Server - Extended Life Cycle Support Extension 6 i386
- Red Hat Enterprise Linux Server - Extended Life Cycle Support Extension (for IBM z Systems) 6 s390x
Fixes
- BZ - 1102343 - service squid restart sometimes leaves duplicate processes
- BZ - 1114714 - When squid returns an ACL tag utilizing an external ACL, sometimes the incorrect tag is used for redirection.
- BZ - 1149588 - (squid): xstrdup: tried to dup a NULL pointer!
- BZ - 1165618 - Malformed ipv6 DNS reverse lookup
- BZ - 1171947 - RFE: Squid - add '--enable-http-violations' configure option
- BZ - 1202858 - [UNRELEASED] restarting testing build of squid results in deleting all files in hard-drive
CVEs
(none)
References
Red Hat Enterprise Linux Server 6
SRPM | |
---|---|
squid-3.1.23-9.el6.src.rpm | SHA-256: 120283504ef30034c7cde2bcc3acae88b0b9ccf6d08ddbc438b3c2a91f550ca7 |
x86_64 | |
squid-3.1.23-9.el6.x86_64.rpm | SHA-256: ad08953e7bf2f6eb7a8f29a844148472c87d478c44edd2112876c7f10479a8aa |
squid-3.1.23-9.el6.x86_64.rpm | SHA-256: ad08953e7bf2f6eb7a8f29a844148472c87d478c44edd2112876c7f10479a8aa |
squid-debuginfo-3.1.23-9.el6.x86_64.rpm | SHA-256: e4ebb4467fa5768af6a327efcb8d930e46b9763f7701e327baded86ab614fae8 |
squid-debuginfo-3.1.23-9.el6.x86_64.rpm | SHA-256: e4ebb4467fa5768af6a327efcb8d930e46b9763f7701e327baded86ab614fae8 |
i386 | |
squid-3.1.23-9.el6.i686.rpm | SHA-256: a0abe96484dceb34eefec2f3eb5ced051dfe714138c2abcca4ecaceda809b08f |
squid-debuginfo-3.1.23-9.el6.i686.rpm | SHA-256: a9cbe7789852e98784939dda84e94296367711d402ed5dc5f37555f1e342180e |
Red Hat Enterprise Linux Server from RHUI 6
SRPM | |
---|---|
squid-3.1.23-9.el6.src.rpm | SHA-256: 120283504ef30034c7cde2bcc3acae88b0b9ccf6d08ddbc438b3c2a91f550ca7 |
x86_64 | |
squid-3.1.23-9.el6.x86_64.rpm | SHA-256: ad08953e7bf2f6eb7a8f29a844148472c87d478c44edd2112876c7f10479a8aa |
squid-debuginfo-3.1.23-9.el6.x86_64.rpm | SHA-256: e4ebb4467fa5768af6a327efcb8d930e46b9763f7701e327baded86ab614fae8 |
i386 | |
squid-3.1.23-9.el6.i686.rpm | SHA-256: a0abe96484dceb34eefec2f3eb5ced051dfe714138c2abcca4ecaceda809b08f |
squid-debuginfo-3.1.23-9.el6.i686.rpm | SHA-256: a9cbe7789852e98784939dda84e94296367711d402ed5dc5f37555f1e342180e |
Red Hat Enterprise Linux Server - Extended Life Cycle Support 6
SRPM | |
---|---|
squid-3.1.23-9.el6.src.rpm | SHA-256: 120283504ef30034c7cde2bcc3acae88b0b9ccf6d08ddbc438b3c2a91f550ca7 |
x86_64 | |
squid-3.1.23-9.el6.x86_64.rpm | SHA-256: ad08953e7bf2f6eb7a8f29a844148472c87d478c44edd2112876c7f10479a8aa |
squid-debuginfo-3.1.23-9.el6.x86_64.rpm | SHA-256: e4ebb4467fa5768af6a327efcb8d930e46b9763f7701e327baded86ab614fae8 |
i386 | |
squid-3.1.23-9.el6.i686.rpm | SHA-256: a0abe96484dceb34eefec2f3eb5ced051dfe714138c2abcca4ecaceda809b08f |
squid-debuginfo-3.1.23-9.el6.i686.rpm | SHA-256: a9cbe7789852e98784939dda84e94296367711d402ed5dc5f37555f1e342180e |
Red Hat Enterprise Linux Workstation 6
SRPM | |
---|---|
squid-3.1.23-9.el6.src.rpm | SHA-256: 120283504ef30034c7cde2bcc3acae88b0b9ccf6d08ddbc438b3c2a91f550ca7 |
x86_64 | |
squid-3.1.23-9.el6.x86_64.rpm | SHA-256: ad08953e7bf2f6eb7a8f29a844148472c87d478c44edd2112876c7f10479a8aa |
squid-debuginfo-3.1.23-9.el6.x86_64.rpm | SHA-256: e4ebb4467fa5768af6a327efcb8d930e46b9763f7701e327baded86ab614fae8 |
i386 | |
squid-3.1.23-9.el6.i686.rpm | SHA-256: a0abe96484dceb34eefec2f3eb5ced051dfe714138c2abcca4ecaceda809b08f |
squid-debuginfo-3.1.23-9.el6.i686.rpm | SHA-256: a9cbe7789852e98784939dda84e94296367711d402ed5dc5f37555f1e342180e |
Red Hat Enterprise Linux for IBM z Systems 6
SRPM | |
---|---|
squid-3.1.23-9.el6.src.rpm | SHA-256: 120283504ef30034c7cde2bcc3acae88b0b9ccf6d08ddbc438b3c2a91f550ca7 |
s390x | |
squid-3.1.23-9.el6.s390x.rpm | SHA-256: 8750e4d91e2e5f730780be6e7856a526c52e075b5cd53005217d8c8b6801a642 |
squid-debuginfo-3.1.23-9.el6.s390x.rpm | SHA-256: 7d380f6f5faff188d28033fcb84c523f6b45ee3a81028392c8770531b101346f |
Red Hat Enterprise Linux for Power, big endian 6
SRPM | |
---|---|
squid-3.1.23-9.el6.src.rpm | SHA-256: 120283504ef30034c7cde2bcc3acae88b0b9ccf6d08ddbc438b3c2a91f550ca7 |
ppc64 | |
squid-3.1.23-9.el6.ppc64.rpm | SHA-256: f196c8df6989aaddcf2a927798880a80752b851a218925a401ba2bcfab35f4eb |
squid-debuginfo-3.1.23-9.el6.ppc64.rpm | SHA-256: 3e0c1a3b614aa5956a0d1a55e223408db12d53307d7918c1e3c6c8c95ac41a31 |
Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 6
SRPM | |
---|---|
squid-3.1.23-9.el6.src.rpm | SHA-256: 120283504ef30034c7cde2bcc3acae88b0b9ccf6d08ddbc438b3c2a91f550ca7 |
s390x | |
squid-3.1.23-9.el6.s390x.rpm | SHA-256: 8750e4d91e2e5f730780be6e7856a526c52e075b5cd53005217d8c8b6801a642 |
squid-debuginfo-3.1.23-9.el6.s390x.rpm | SHA-256: 7d380f6f5faff188d28033fcb84c523f6b45ee3a81028392c8770531b101346f |
Red Hat Enterprise Linux Server - Extended Life Cycle Support Extension 6
SRPM | |
---|---|
squid-3.1.23-9.el6.src.rpm | SHA-256: 120283504ef30034c7cde2bcc3acae88b0b9ccf6d08ddbc438b3c2a91f550ca7 |
x86_64 | |
squid-3.1.23-9.el6.x86_64.rpm | SHA-256: ad08953e7bf2f6eb7a8f29a844148472c87d478c44edd2112876c7f10479a8aa |
squid-debuginfo-3.1.23-9.el6.x86_64.rpm | SHA-256: e4ebb4467fa5768af6a327efcb8d930e46b9763f7701e327baded86ab614fae8 |
i386 | |
squid-3.1.23-9.el6.i686.rpm | SHA-256: a0abe96484dceb34eefec2f3eb5ced051dfe714138c2abcca4ecaceda809b08f |
squid-debuginfo-3.1.23-9.el6.i686.rpm | SHA-256: a9cbe7789852e98784939dda84e94296367711d402ed5dc5f37555f1e342180e |
Red Hat Enterprise Linux Server - Extended Life Cycle Support Extension (for IBM z Systems) 6
SRPM | |
---|---|
squid-3.1.23-9.el6.src.rpm | SHA-256: 120283504ef30034c7cde2bcc3acae88b0b9ccf6d08ddbc438b3c2a91f550ca7 |
s390x | |
squid-3.1.23-9.el6.s390x.rpm | SHA-256: 8750e4d91e2e5f730780be6e7856a526c52e075b5cd53005217d8c8b6801a642 |
squid-debuginfo-3.1.23-9.el6.s390x.rpm | SHA-256: 7d380f6f5faff188d28033fcb84c523f6b45ee3a81028392c8770531b101346f |
The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.