Affected Versions:
Squid Web Proxy Cache 3.1.6
Squid Web Proxy Cache 3.1.5.1 vulnerability description:
Squid is an efficient Web Cache and proxy program. It was initially developed for the Unix platform and has been transplanted to Linux and most Unix systems, the latest Squid can run on Windows.
Squid has a logical error when processing the received long DNS response. If the Squid server is not configured with an IPv6 parser, dns_internal.cc obtains the TC flag from the server when the response exceeds 512 bytes and tries to query through TCP instead of UDP. Squid initiates a TCP connection and mistakenly considers that an ipv6 dns query is being sent, triggering an Assertion error. <* Reference
Http://secunia.com/advisories/41090/
Http://marc.info /? L = squid-users & m = 128263555724981 & w = 2
Http://bugs.squid-cache.org/show_bug.cgi? Format = multiple & amp; id = 3021
*>
Vendor patch:
Squid
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.squid-cache.org/Versions/v3/3.1/
Ftp://ftp.squid-cache.org/pub/squid/
Ftp://ftp.squid-cache.org/pub/archive/3.1/