—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA1
Liebe Kolleginnen und Kollegen,
soeben erreichte uns nachfolgendes Fedora Security Advisory. Wir geben
diese Informationen unveraendert an Sie weiter.
CVE-2010-0308 – Assertion Failure in der Funktion rfc1035NameUnpack()
Die Funktion rfc1035NameUnpack() in lib/rfc1035.c enthaelt einen
Fehler, der es einem entfernten Angreifer ermoeglicht, mittels eines
speziell praeparierten DNS-Pakets einen Denial-of-Service Angriff
auszufuehren.
Betroffen sind die folgenden Software Pakete und Plattformen:
Paket squid
Fedora 11
Vom Hersteller werden ueberarbeitete Pakete zur Verfuegung gestellt.
Hersteller Advisory:
http://lists.fedoraproject.org/pipermail/package-announce/2010-March/037159.html
(c) der deutschen Zusammenfassung bei DFN-CERT Services GmbH; die
Verbreitung, auch auszugsweise, ist nur unter Hinweis auf den Urheber,
DFN-CERT Services GmbH, und nur zu nicht kommerziellen Zwecken
gestattet.
Mit freundlichen Gruessen,
Detlev O. Matthies
– —
Detlev O. Matthies, M.Sc. (Incident Response Team)
DFN-CERT Services GmbH, https://www.dfn-cert.de, Phone +49 40 808077-590
Sitz / Register: Hamburg, AG Hamburg, HRB 88805, Ust-IdNr.: DE 232129737
Sachsenstrasse 5, 20097 Hamburg/Germany, CEO: Dr. Klaus-Peter Kossakowski
Automatische Warnmeldungen https://www.cert.dfn.de/autowarn
– ——————————————————————————–
Fedora Update Notification
FEDORA-2010-2434
2010-02-21 20:51:04
– ——————————————————————————–
Name : squid
Product : Fedora 11
Version : 3.0.STABLE24
Release : 1.fc11
URL : http://www.squid-cache.org
Summary : The Squid proxy caching server
Description :
Squid is a high-performance proxy caching server for Web clients,
supporting FTP, gopher, and HTTP data objects. Unlike traditional
caching software, Squid handles all requests in a single,
non-blocking, I/O-driven process. Squid keeps meta data and especially
hot objects cached in RAM, caches DNS lookups, supports non-blocking
DNS lookups, and implements negative caching of failed requests.
Squid consists of a main server program squid, a Domain Name System
lookup program (dnsserver), a program for retrieving FTP data
(ftpget), and some management and client tools.
– ——————————————————————————–
Update Information:
Denial of service issue in HTCP processing (SQUID-2010:2) http://www.squid-
cache.org/Advisories/SQUID-2010_2.txt
– ——————————————————————————–
ChangeLog:
* Fri Feb 12 2010 Henrik Nordstrom
– – Upgrade to 3.0.STABLE24 fixing HTCP related DoS issue (Squid-2010:2)
* Wed Feb 3 2010 Henrik Nordstrom
– – Upgrade to 3.0.STABLE23 with correct DNS DoS fix (Squid-2010:1, CVE-2010-0308)
* Sat Jan 9 2010 Henrik Nordstrom
– – Bug #551302 Added missing libcap dependency for increased security
* Sat Jan 9 2010 Henrik Nordstrom
– – Update to 3.0.STABLE21, improving stability and fixing FTP error display
* Mon Nov 23 2009 Jiri Skala
– – fixed #532930 Syntactic error in /etc/init.d/squid
– – fixed #528453 cannot initialize cache_dir with user specified config file
* Sat Oct 31 2009 Henrik Nordstrom
– – Update to 3.0.STABLE20, with several important bugfixes among
one client cache corruption issue (mixup of 304 responses).
* Sat Sep 19 2009 Henrik Nordstrom
– – Patch for Squid Bug #2626: Invalid response for IMS request
* Fri Sep 11 2009 Henrik Nordstrom
– – Update to 3.0.STABLE19
* Tue Sep 1 2009 Henrik Nordstrom
– – Bug #520445 silence logrotate when Squid is not running
* Tue Aug 4 2009 Henrik Nordstrom
– – Update to 3.0.STABLE18
* Sat Aug 1 2009 Henrik Nordstrom
– – Squid Bug #2728: regression: assertion failed: http.cc:705: “!eof”
* Mon Jul 27 2009 Henrik Nordstrom
– – Bug #514014, update to 3.0.STABLE17 fixing the denial of service issues
mentioned in Squid security advisory SQUID-2009_2.
* Wed Jul 1 2009 Jiri Skala
– – fixed patch parameter of bXXX patches
* Mon Jun 29 2009 Henrik Nordstrom
– – Upgrade to 3.0.STABLE16
* Sat May 23 2009 Henrik Nordstrom
– – Bug #453304 – Squid requires restart after Network Manager connection setup
* Sat May 9 2009 Henrik Nordstrom
– – Upgrade to 3.0.STABLE15
* Tue Apr 28 2009 Jiri Skala
– – fixed ambiguous condition in the init script (exit 4)
* Mon Apr 20 2009 Henrik Nordstrom
– – Squid bug #2635: assertion failed: HttpHeader.cc:1196: “Headers[id].type == ftInt64”
* Sun Apr 19 2009 Henrik Nordstrom
– – Upgrade to 3.0.STABLE14
* Fri Mar 6 2009 Henrik Nordstrom
– – backported logfile.cc syslog parameters patch from 3.1 (b9443.patch)
– – GCC-4.4 workaround in src/wccp2.cc
* Wed Feb 25 2009 Fedora Release Engineering
– – Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild
– ——————————————————————————–
References:
[ 1 ] Bug #565426 – squid: HTCP packet temporary DoS (SQUID-2010:2)
https://bugzilla.redhat.com/show_bug.cgi?id=565426
– ——————————————————————————–
This update can be installed with the “yum” update program. Use
su -c ‘yum update squid’ at the command line.
For more information, refer to “Managing Software with yum”,
available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
– ——————————————————————————–
—–BEGIN PGP SIGNATURE—–
Version: GnuPG v1.4.2 (GNU/Linux)
iD8DBQFLninzWmhIvjFb90URAggeAJ4lpj0rAjq8ZfkdV7eYY77uUnD2QwCfZsWW
YCH+R5Nz5AsE4H7iK5bjEQg=
=e0xV
—–END PGP SIGNATURE—–