Oval Definition:oval:com.redhat.rhsa:def:20070131
Revision Date:2007-04-03Version:635
Title:RHSA-2007:0131: squid security update (Moderate)
Description:Squid is a high-performance proxy caching server for Web clients, supporting FTP, gopher, and HTTP data objects.

  • A denial of service flaw was found in the way Squid processed the TRACE request method. It was possible for an attacker behind the Squid proxy to issue a malformed TRACE request, crashing the Squid daemon child process. As long as these requests were sent, it would prevent legitimate usage of the proxy server. (CVE-2007-1560)

    This flaw does not affect the version of Squid shipped in Red Hat Enterprise Linux 2.1, 3, or 4.

    Users of Squid should upgrade to this updated package, which contains a backported patch and is not vulnerable to this issue.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2007-1560
    RHSA-2007:0131
    RHSA-2007:0131-01
    RHSA-2007:0131-01
    Platform(s):Red Hat Enterprise Linux 5
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 5 is installed
  • AND squid is earlier than 7:2.6.STABLE6-4.el5
  • AND squid is signed with Red Hat redhatrelease2 key
  • BACK