Release date:
Updated on:
Affected Systems:
Squid 3.2.7
Squid 3.2.5
Description:
--------------------------------------------------------------------------------
Bugtraq id: 58322
Squid is an efficient Web Cache and proxy program.
Squid 2.7.Stable9 has a security vulnerability in the implementation of the 'httpmakevarymark () 'function. After successful exploitation, remote attackers can execute arbitrary code in the context of the affected application.
<* Source: tytusromekiatomek (tytusromekiatomek@hushmail.com)
Link: http://seclists.org/fulldisclosure/2013/Mar/62
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Squid
-----
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.squid-cache.org/Advisories/