Lucene search

K
redhatRedHatRHSA-2008:0214
HistoryApr 08, 2008 - 12:00 a.m.

(RHSA-2008:0214) Moderate: squid security update

2008-04-0800:00:00
access.redhat.com
20

EPSS

0.009

Percentile

83.0%

Squid is a high-performance proxy caching server for Web clients,
supporting FTP, gopher, and HTTP data objects.

A flaw was found in the way squid manipulated HTTP headers for cached
objects stored in system memory. An attacker could use this flaw to cause a
squid child process to exit. This interrupted existing connections and made
proxy services unavailable. Note: the parent squid process started a new
child process, so this attack only resulted in a temporary denial of
service. (CVE-2008-1612)

Users of squid are advised to upgrade to these updated packages, which
contain a backported patch to resolve this issue.