受影响系统:
Conectiva Linux 10.0
S.u.S.E. Linux Enterprise Server 9
S.u.S.E. Linux Enterprise Server 8
S.u.S.E. Linux Enterprise Server 7
S.u.S.E. Linux 9.3 x86_64
S.u.S.E. Linux 9.3
S.u.S.E. Linux 9.2 x86_64
S.u.S.E. Linux 9.2
S.u.S.E. Linux 9.1 x86_64
S.u.S.E. Linux 9.1
S.u.S.E. Linux 9.0 x86_64
S.u.S.E. Linux 9.0
S.u.S.E. Linux 8.2
SCO Unixware 7.1.4
SGI ProPack 3.0 SP6
TurboLinux TL Server 8.0
TurboLinux TL Server 7.0
TurboLinux TL Server 10.0
TurboLinux TL Workstation 8.0
TurboLinux TL Workstation 7.0
OpenPKG OpenPKG Current
OpenPKG OpenPKG 2.4
OpenPKG OpenPKG 2.3
RedHat Enterprise Linux WS 4
RedHat Enterprise Linux WS 3
RedHat Enterprise Linux WS 2.1
RedHat Enterprise Linux ES 4
RedHat Enterprise Linux ES 3
RedHat Enterprise Linux ES 2.1
RedHat Enterprise Linux AS 4
RedHat Enterprise Linux AS 3
RedHat Enterprise Linux AS 2.1 IA64
RedHat Enterprise Linux AS 2.1
Squid Web Proxy Cache <= 2.5.STABLE10
RedHat Desktop 4.0
RedHat Desktop 3.0
RedHat Advanced Workstation 2.1 IA64
RedHat Advanced Workstation 2.1
TurboLinux Appliance Server Workgroup Edition 1.0
TurboLinux Appliance Server Hosting Edition 1.0
详细描述:
Squid是一个高效的Web缓存及代理程序,最初是为Unix平台开发的,现在也被移植到Linux和大多数的Unix类系统中。最新的Squid可以运行在Windows平台下。
Squid 2.5.STABLE10及更早版本的store.c允许远程攻击者发送可以触发有关STORE_PENDING断言错误的终止请求,导致sslConnectTimeout函数中出现分段错误,造成Squid崩溃。
补丁下载:
http://www.squid-cache.org/Versions/v2/2.5/bugs/squid-2.5.STABLE10-STORE_PENDING.patch
-
相关文章