Oval Definition:oval:com.redhat.rhsa:def:20152378
Revision Date:2015-11-19Version:646
Title:RHSA-2015:2378: squid security and bug fix update (Moderate)
Description:Squid is a high-performance proxy caching server for web clients, supporting FTP, Gopher, and HTTP data objects.

  • It was found that Squid configured with client-first SSL-bump did not correctly validate X.509 server certificate host name fields. A man-in-the-middle attacker could use this flaw to spoof a Squid server using a specially crafted X.509 certificate. (CVE-2015-3455)

    This update fixes the following bugs:

  • Previously, the squid process did not handle file descriptors correctly when receiving Simple Network Management Protocol (SNMP) requests. As a consequence, the process gradually accumulated open file descriptors. This bug has been fixed and squid now handles SNMP requests correctly, closing file descriptors when necessary. (BZ#1198778)

  • Under high system load, the squid process sometimes terminated unexpectedly with a segmentation fault during reboot. This update provides better memory handling during reboot, thus fixing this bug. (BZ#1225640)

    Users of squid are advised to upgrade to these updated packages, which fix these bugs. After installing this update, the squid service will be restarted automatically.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2015-3455
    RHSA-2015:2378
    RHSA-2015:2378-00
    RHSA-2015:2378-03
    Platform(s):Red Hat Enterprise Linux 7
    Red Hat Enterprise Linux 7 (please do not use for >= RHEL-7.5)
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 7 is installed
  • AND
  • squid is earlier than 7:3.3.8-26.el7
  • AND squid is signed with Red Hat redhatrelease2 key
  • squid-sysvinit is earlier than 7:3.3.8-26.el7
  • AND squid-sysvinit is signed with Red Hat redhatrelease2 key
  • Definition Synopsis
  • Release Information
  • Red Hat Enterprise Linux 7 Client is installed
  • OR Red Hat Enterprise Linux 7 Server is installed
  • OR Red Hat Enterprise Linux 7 Workstation is installed
  • OR Red Hat Enterprise Linux 7 ComputeNode is installed
  • AND Package Information
  • squid-sysvinit is earlier than 7:3.3.8-26.el7
  • AND squid-sysvinit is signed with Red Hat redhatrelease2 key
  • OR
  • squid is earlier than 7:3.3.8-26.el7
  • AND squid is signed with Red Hat redhatrelease2 key
  • BACK