Summary
The remote host is missing an update to squid
announced via advisory MDVSA-2009:161.
Solution
To upgrade automatically use MandrakeUpdate or urpmi. The verification of md5 checksums and GPG signatures is performed automatically for you.
https://secure1.securityspace.com/smysecure/catid.html?in=MDVSA-2009:161 http://www.squid-cache.org/Advisories/SQUID-2009_2.txt
Insight
Multiple vulnerabilities has been found and corrected in squid:
Due to incorrect buffer limits and related bound checks Squid is vulnerable to a denial of service attack when processing specially crafted requests or responses.
Due to incorrect data validation Squid is vulnerable to a denial of service attack when processing specially crafted responses.
This update provides fixes for these vulnerabilities.
Affected: 2008.1, 2009.0, 2009.1
Severity
Classification
-
CVE CVE-2009-2621, CVE-2009-2622 -
CVSS Base Score: 5.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
Related Vulnerabilities