Affected Versions:
Squid Web Proxy Cache 3.2 Squid Web Proxy Cache 3.1 Squid Web Proxy Cache 3.0
Vulnerability description:
Bugtraq id: 42982Squid is an efficient Web Cache and proxy program, initially developed for the Unix platform,
Now it has been transplanted to Linux and most Unix systems, and the latest Squid can run on Windows. Some Squid internal string processing routines do not properly check the NULL pointer. Remote attackers can cause DoS by sending malicious requests.
<* Reference
Http://secunia.com/advisories/41298/
Http://www.squid-cache.org/Advisories/SQUID-2010_3.txt
*>
Temporary solution: if you cannot install or upgrade the patch immediately, NSFOCUS recommends that you take the following measures to reduce the threat: 1) ignore_expect_100 squid. the conf option is set to off (default), or completely from squid. conf. 2) Compile Squid -- disable-http-violations. Vendor patch: Squid ----- the current vendor has released the upgrade patch to fix this security problem, please go to the vendor's home page download: http://www.squid-cache.org/Versions/v3/3.0/changesets/squid-3.0-9189.patchhttp://www.squid-cache.org/Versions/v3/3.1/changesets/squid-3.1-10090.patch