Skip to navigation

Security Advisory Moderate: squid security update

Advisory: RHSA-2011:1791-1
Type: Security Advisory
Severity: Moderate
Issued on: 2011-12-06
Last updated on: 2011-12-06
Affected Products: Red Hat Enterprise Linux Server (v. 6)
Red Hat Enterprise Linux Server AUS (v. 6.2)
Red Hat Enterprise Linux Server EUS (v. 6.2.z)
Red Hat Enterprise Linux Workstation (v. 6)
CVEs (cve.mitre.org): CVE-2011-4096

Details

An updated squid package that fixes one security issue is now available for
Red Hat Enterprise Linux 6.

The Red Hat Security Response Team has rated this update as having moderate
security impact. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available from the CVE link in
the References section.

Squid is a high-performance proxy caching server for web clients,
supporting FTP, Gopher, and HTTP data objects.

An input validation flaw was found in the way Squid calculated the total
number of resource records in the answer section of multiple name server
responses. An attacker could use this flaw to cause Squid to crash.
(CVE-2011-4096)

Users of squid should upgrade to this updated package, which contains a
backported patch to correct this issue. After installing this update, the
squid service will be restarted automatically.


Solution

Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/kb/docs/DOC-11259

Updated packages

Red Hat Enterprise Linux Server (v. 6)

SRPMS:
squid-3.1.10-1.el6_2.1.src.rpm
File outdated by:  RHBA-2014:0048
    MD5: 516aa8188bd5b3c5b9c3f2cc9ff082bb
SHA-256: 32ed0fbf41b63bf34831fd2daef9946c303b2b37e0eacfb667c46e11adfeb9a5
 
IA-32:
squid-3.1.10-1.el6_2.1.i686.rpm
File outdated by:  RHBA-2014:0048
    MD5: 79eb7539649a1fb6dea1497616255908
SHA-256: 58224e4521b63b7941697bbde2a63349aa45dc7664bbfc31abc1395ff2767885
squid-debuginfo-3.1.10-1.el6_2.1.i686.rpm
File outdated by:  RHBA-2014:0048
    MD5: 8999f55d97ba39940fdedf37d8fb40f8
SHA-256: c21d80f90748ace75c281761932f1a7188a3dd9e9aa28cc8ef970aec1cfe92a7
 
PPC:
squid-3.1.10-1.el6_2.1.ppc64.rpm
File outdated by:  RHBA-2014:0048
    MD5: a0d88a12e61e8766bae45f17b8c9727c
SHA-256: baadde2772f05c14b7f9f2039ba7b781827ceb1cd639b98c7809d8e9e52270a3
squid-debuginfo-3.1.10-1.el6_2.1.ppc64.rpm
File outdated by:  RHBA-2014:0048
    MD5: 93745eb49454a20cd87bd4890df9c772
SHA-256: 6071419506ae36bddd75405ba856df6599f1104b683f26d0898c96b3cba7c870
 
s390x:
squid-3.1.10-1.el6_2.1.s390x.rpm
File outdated by:  RHBA-2014:0048
    MD5: 0df20be3a5c0720ea08b55b09c16544a
SHA-256: b556a40eb8053e64242e2724fc47c51265c726a3277ec1225dd33875126674a2
squid-debuginfo-3.1.10-1.el6_2.1.s390x.rpm
File outdated by:  RHBA-2014:0048
    MD5: fada99157754fe1f98c95327c4df3231
SHA-256: d678b5181745ba905d44b3ef4bd1bd25239128b37db2c7b6c471ebd95af3c320
 
x86_64:
squid-3.1.10-1.el6_2.1.x86_64.rpm
File outdated by:  RHBA-2014:0048
    MD5: 61a511ea712118f283c4d2527a796d96
SHA-256: 19543a253a41339c80cc44c1777c8d1c2d8e263a69f999af8ffe3ef948a0a0ae
squid-debuginfo-3.1.10-1.el6_2.1.x86_64.rpm
File outdated by:  RHBA-2014:0048
    MD5: fd5c483795e98f3c3a26b0d9ada23b05
SHA-256: efad0bf7d9948a3c0400cffb05e35a52f381cc230171931436b2f3a71836fde6
 
Red Hat Enterprise Linux Server AUS (v. 6.2)

SRPMS:
squid-3.1.10-1.el6_2.1.src.rpm
File outdated by:  RHBA-2014:0048
    MD5: 516aa8188bd5b3c5b9c3f2cc9ff082bb
SHA-256: 32ed0fbf41b63bf34831fd2daef9946c303b2b37e0eacfb667c46e11adfeb9a5
 
x86_64:
squid-3.1.10-1.el6_2.1.x86_64.rpm
File outdated by:  RHBA-2012:0557
    MD5: 61a511ea712118f283c4d2527a796d96
SHA-256: 19543a253a41339c80cc44c1777c8d1c2d8e263a69f999af8ffe3ef948a0a0ae
squid-debuginfo-3.1.10-1.el6_2.1.x86_64.rpm
File outdated by:  RHBA-2012:0557
    MD5: fd5c483795e98f3c3a26b0d9ada23b05
SHA-256: efad0bf7d9948a3c0400cffb05e35a52f381cc230171931436b2f3a71836fde6
 
Red Hat Enterprise Linux Server EUS (v. 6.2.z)

SRPMS:
squid-3.1.10-1.el6_2.1.src.rpm
File outdated by:  RHBA-2014:0048
    MD5: 516aa8188bd5b3c5b9c3f2cc9ff082bb
SHA-256: 32ed0fbf41b63bf34831fd2daef9946c303b2b37e0eacfb667c46e11adfeb9a5
 
IA-32:
squid-3.1.10-1.el6_2.1.i686.rpm
File outdated by:  RHBA-2012:0557
    MD5: 79eb7539649a1fb6dea1497616255908
SHA-256: 58224e4521b63b7941697bbde2a63349aa45dc7664bbfc31abc1395ff2767885
squid-debuginfo-3.1.10-1.el6_2.1.i686.rpm
File outdated by:  RHBA-2012:0557
    MD5: 8999f55d97ba39940fdedf37d8fb40f8
SHA-256: c21d80f90748ace75c281761932f1a7188a3dd9e9aa28cc8ef970aec1cfe92a7
 
PPC:
squid-3.1.10-1.el6_2.1.ppc64.rpm
File outdated by:  RHBA-2012:0557
    MD5: a0d88a12e61e8766bae45f17b8c9727c
SHA-256: baadde2772f05c14b7f9f2039ba7b781827ceb1cd639b98c7809d8e9e52270a3
squid-debuginfo-3.1.10-1.el6_2.1.ppc64.rpm
File outdated by:  RHBA-2012:0557
    MD5: 93745eb49454a20cd87bd4890df9c772
SHA-256: 6071419506ae36bddd75405ba856df6599f1104b683f26d0898c96b3cba7c870
 
s390x:
squid-3.1.10-1.el6_2.1.s390x.rpm
File outdated by:  RHBA-2012:0557
    MD5: 0df20be3a5c0720ea08b55b09c16544a
SHA-256: b556a40eb8053e64242e2724fc47c51265c726a3277ec1225dd33875126674a2
squid-debuginfo-3.1.10-1.el6_2.1.s390x.rpm
File outdated by:  RHBA-2012:0557
    MD5: fada99157754fe1f98c95327c4df3231
SHA-256: d678b5181745ba905d44b3ef4bd1bd25239128b37db2c7b6c471ebd95af3c320
 
x86_64:
squid-3.1.10-1.el6_2.1.x86_64.rpm
File outdated by:  RHBA-2012:0557
    MD5: 61a511ea712118f283c4d2527a796d96
SHA-256: 19543a253a41339c80cc44c1777c8d1c2d8e263a69f999af8ffe3ef948a0a0ae
squid-debuginfo-3.1.10-1.el6_2.1.x86_64.rpm
File outdated by:  RHBA-2012:0557
    MD5: fd5c483795e98f3c3a26b0d9ada23b05
SHA-256: efad0bf7d9948a3c0400cffb05e35a52f381cc230171931436b2f3a71836fde6
 
Red Hat Enterprise Linux Workstation (v. 6)

SRPMS:
squid-3.1.10-1.el6_2.1.src.rpm
File outdated by:  RHBA-2014:0048
    MD5: 516aa8188bd5b3c5b9c3f2cc9ff082bb
SHA-256: 32ed0fbf41b63bf34831fd2daef9946c303b2b37e0eacfb667c46e11adfeb9a5
 
IA-32:
squid-3.1.10-1.el6_2.1.i686.rpm
File outdated by:  RHBA-2014:0048
    MD5: 79eb7539649a1fb6dea1497616255908
SHA-256: 58224e4521b63b7941697bbde2a63349aa45dc7664bbfc31abc1395ff2767885
squid-debuginfo-3.1.10-1.el6_2.1.i686.rpm
File outdated by:  RHBA-2014:0048
    MD5: 8999f55d97ba39940fdedf37d8fb40f8
SHA-256: c21d80f90748ace75c281761932f1a7188a3dd9e9aa28cc8ef970aec1cfe92a7
 
x86_64:
squid-3.1.10-1.el6_2.1.x86_64.rpm
File outdated by:  RHBA-2014:0048
    MD5: 61a511ea712118f283c4d2527a796d96
SHA-256: 19543a253a41339c80cc44c1777c8d1c2d8e263a69f999af8ffe3ef948a0a0ae
squid-debuginfo-3.1.10-1.el6_2.1.x86_64.rpm
File outdated by:  RHBA-2014:0048
    MD5: fd5c483795e98f3c3a26b0d9ada23b05
SHA-256: efad0bf7d9948a3c0400cffb05e35a52f381cc230171931436b2f3a71836fde6
 
(The unlinked packages above are only available from the Red Hat Network)

Bugs fixed (see bugzilla for more information)

750316 - CVE-2011-4096 squid: Invalid free by processing CNAME DNS record pointing to another CNAME record pointing to an empty A-record


References



These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from:
https://www.redhat.com/security/team/key/#package

The Red Hat security contact is secalert@redhat.com. More contact details at http://www.redhat.com/security/team/contact/