Oval Definition:oval:com.redhat.rhsa:def:20111293
Revision Date:2011-09-14Version:636
Title:RHSA-2011:1293: squid security update (Moderate)
Description:Squid is a high-performance proxy caching server for web clients, supporting FTP, Gopher, and HTTP data objects.

  • A buffer overflow flaw was found in the way Squid parsed replies from remote Gopher servers. A remote user allowed to send Gopher requests to a Squid proxy could possibly use this flaw to cause the squid child process to crash or execute arbitrary code with the privileges of the squid user, by making Squid perform a request to an attacker-controlled Gopher server. (CVE-2011-3205)

    Users of squid should upgrade to this updated package, which contains a backported patch to correct this issue. After installing this update, the squid service will be restarted automatically.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2011-3205
    CVE-2011-3205
    RHSA-2011:1293
    RHSA-2011:1293-01
    RHSA-2011:1293-01
    Platform(s):Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND squid is earlier than 7:3.1.10-1.el6_1.1
  • AND squid is signed with Red Hat redhatrelease2 key
  • BACK