Oval Definition:oval:com.redhat.rhsa:def:20110545
Revision Date:2011-05-19Version:648
Title:RHSA-2011:0545: squid security and bug fix update (Low)
Description:Squid is a high-performance proxy caching server for web clients, supporting FTP, Gopher, and HTTP data objects.

  • It was found that string comparison functions in Squid did not properly handle the comparisons of NULL and empty strings. A remote, trusted web client could use this flaw to cause the squid daemon to crash via a specially-crafted request. (CVE-2010-3072)

    This update also fixes the following bugs:

  • A small memory leak in Squid caused multiple "ctx: enter level" messages to be logged to "/var/log/squid/cache.log". This update resolves the memory leak. (BZ#666533)

  • This erratum upgrades Squid to upstream version 3.1.10. This upgraded version supports the Google Instant service and introduces various code improvements. (BZ#639365)

    Users of squid should upgrade to this updated package, which resolves these issues. After installing this update, the squid service will be restarted automatically.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2010-3072
    CVE-2010-3072
    RHSA-2011:0545
    RHSA-2011:0545-01
    RHSA-2011:0545-01
    Platform(s):Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND squid is earlier than 7:3.1.10-1.el6
  • AND squid is signed with Red Hat redhatrelease2 key
  • BACK