Release date:
Updated on: 2013-07-12
Affected Systems:
Squid 3.x
Description:
--------------------------------------------------------------------------------
Squid is an efficient Web Cache and proxy program.
When Squid 3.2-3.2.11 and 3.3-3.3.6 process DNS query generation requests, the "idnsALookup ()" function fails. Attackers can exploit this vulnerability by sending specially crafted HTTP requests to cause buffer overflow.
<* Source: Nathan Hoad
Netbox Blue
Link: http://secunia.com/advisories/54076/
Http://www.squid-cache.org/Advisories/SQUID-2013_2.txt
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Squid
-----
Squid has released a Security Bulletin (SQUID-2013_2) and corresponding patches for this:
SQUID-2013_2: Buffer overflow in HTTP request handling
Link: http://www.squid-cache.org/Advisories/SQUID-2013_2.txt
Patch download:
Squid 3.0:
Http://www.squid-cache.org/Versions/v3/3.0/changesets/squid-3.0-9200.patch
Squid 3.1:
Http://www.squid-cache.org/Versions/v3/3.1/changesets/squid-3.1-10487.patch
Squid 3.2:
Http://www.squid-cache.org/Versions/v3/3.2/changesets/squid-3.2-11823.patch
Squid 3.3:
Http://www.squid-cache.org/Versions/v3/3.3/changesets/squid-3.3-12587.patch