Squid is prone to a remote denial-of-service vulnerability because the proxy server fails to perform boundary checks before copying user-supplied data into process buffers. Successfully exploiting this issue allows remote attackers to crash the affected application, denying further service to legitimate users. Attackers may also be able to execute arbitrary code, but this has not been confirmed. This issue affects Squid 2.6.STABLE16 and prior versions. All Squid-3 snapshots and prereleases up to the November 28 snapshot are also vulnerable. Squid Web Proxy Cache 3.0 PRE3 Squid Web Proxy Cache 3.0 PRE2 Squid Web Proxy Cache 3.0 PRE1 Squid Web Proxy Cache 3.0 Squid Web Proxy Cache 2.5 .STABLE9 + Debian Linux 3.1 sparc + Debian Linux 3.1 s/390 + Debian Linux 3.1 ppc + Debian Linux 3.1 mipsel + Debian Linux 3.1 mips + Debian Linux 3.1 m68k + Debian Linux 3.1 ia-64 + Debian Linux 3.1 ia-32 + Debian Linux 3.1 hppa + Debian Linux 3.1 arm + Debian Linux 3.1 amd64 + Debian Linux 3.1 alpha +...
Squid is prone to a remote denial-of-service vulnerability because the proxy server fails to perform boundary checks before copying user-supplied data into process buffers. Successfully exploiting this issue allows remote attackers to crash the affected application, denying further service to legitimate users. Attackers may also be able to execute arbitrary code, but this has not been confirmed. This issue affects Squid 2.6.STABLE16 and prior versions. All Squid-3 snapshots and prereleases up to the November 28 snapshot are also vulnerable. Squid Web Proxy Cache 3.0 PRE3 Squid Web Proxy Cache 3.0 PRE2 Squid Web Proxy Cache 3.0 PRE1 Squid Web Proxy Cache 3.0 Squid Web Proxy Cache 2.5 .STABLE9 + Debian Linux 3.1 sparc + Debian Linux 3.1 s/390 + Debian Linux 3.1 ppc + Debian Linux 3.1 mipsel + Debian Linux 3.1 mips + Debian Linux 3.1 m68k + Debian Linux 3.1 ia-64 + Debian Linux 3.1 ia-32 + Debian Linux 3.1 hppa + Debian Linux 3.1 arm + Debian Linux 3.1 amd64 + Debian Linux 3.1 alpha + Debian Linux 3.1 + MandrakeSoft Corporate Server 3.0 x86_64 + MandrakeSoft Corporate Server 3.0 + MandrakeSoft Linux Mandrake 10.2 x86_64 + MandrakeSoft Linux Mandrake 10.2 + MandrakeSoft Linux Mandrake 10.1 x86_64 + MandrakeSoft Linux Mandrake 10.1 + MandrakeSoft Linux Mandrake 10.0 AMD64 + MandrakeSoft Linux Mandrake 10.0 Squid Web Proxy Cache 2.5 .STABLE8 + Gentoo Linux + RedHat Fedora Core3 + RedHat Fedora Core2 + Ubuntu Ubuntu Linux 5.0 4 powerpc + Ubuntu Ubuntu Linux 5.0 4 i386 + Ubuntu Ubuntu Linux 5.0 4 amd64 Squid Web Proxy Cache 2.5 .STABLE7 + Conectiva Linux 10.0 + Conectiva Linux 9.0 + Gentoo Linux + RedHat Fedora Core3 + RedHat Fedora Core2 Squid Web Proxy Cache 2.5 .STABLE6 + MandrakeSoft Linux Mandrake 10.1 x86_64 + S.u.S.E. Linux Personal 9.2 x86_64 + S.u.S.E. Linux Personal 9.2 + Turbolinux Appliance Server 1.0 Workgroup Edition + Turbolinux Appliance Server 1.0 Hosting Edition + Turbolinux Appliance Server Hosting Edition 1.0 + Turbolinux Appliance Server Workgroup Edition 1.0 + Turbolinux Turbolinux Server 10.0 + Turbolinux Turbolinux Server 8.0 + Turbolinux Turbolinux Server 7.0 + Turbolinux Turbolinux Workstation 8.0 + Turbolinux Turbolinux Workstation 7.0 Squid Web Proxy Cache 2.5 .STABLE5 + Conectiva Linux 10.0 + Conectiva Linux 9.0 + S.u.S.E. Linux Personal 9.1 x86_64 + S.u.S.E. Linux Personal 9.1 + Trustix Secure Linux 2.1 + Trustix Secure Linux 2.0 + Ubuntu Ubuntu Linux 4.1 ppc + Ubuntu Ubuntu Linux 4.1 ia64 + Ubuntu Ubuntu Linux 4.1 ia32 Squid Web Proxy Cache 2.5 .STABLE4 + MandrakeSoft Corporate Server 3.0 + MandrakeSoft Linux Mandrake 10.0 AMD64 + MandrakeSoft Linux Mandrake 10.0 + OpenPKG OpenPKG 2.0 + OpenPKG OpenPKG Current Squid Web Proxy Cache 2.5 .STABLE3 + MandrakeSoft Linux Mandrake 9.2 amd64 + MandrakeSoft Linux Mandrake 9.2 + OpenPKG OpenPKG 1.3 + RedHat Desktop 3.0 + RedHat Enterprise Linux WS 3 + RedHat Enterprise Linux ES 3 + RedHat Enterprise Linux AS 3 + RedHat Fedora Core1 + S.u.S.E. Linux Personal 9.0 x86_64 + S.u.S.E. Linux Personal 9.0 Squid Web Proxy Cache 2.5 .STABLE10 Squid Web Proxy Cache 2.5 .STABLE10 Squid Web Proxy Cache 2.5 .STABLE1 + MandrakeSoft Linux Mandrake 9.1 ppc + MandrakeSoft Linux Mandrake 9.1 + S.u.S.E. Linux Personal 8.2 Squid Web Proxy Cache 2.4 .STABLE7 + MandrakeSoft Corporate Server 2.1 x86_64 + MandrakeSoft Corporate Server 2.1 + MandrakeSoft Multi Network Firewall 2.0 + RedHat Enterprise Linux WS 2.1 IA64 + RedHat Enterprise Linux WS 2.1 + RedHat Enterprise Linux ES 2.1 IA64 + RedHat Enterprise Linux ES 2.1 + RedHat Enterprise Linux AS 2.1 IA64 + RedHat Enterprise Linux AS 2.1 + RedHat Linux Advanced Work Station 2.1 Squid Web Proxy Cache 2.4 .STABLE6 + Debian Linux 3.0 sparc + Debian Linux 3.0 s/390 + Debian Linux 3.0 ppc + Debian Linux 3.0 mipsel + Debian Linux 3.0 mips + Debian Linux 3.0 m68k + Debian Linux 3.0 ia-64 + Debian Linux 3.0 ia-32 + Debian Linux 3.0 hppa + Debian Linux 3.0 arm + Debian Linux 3.0 alpha + Debian Linux 3.0 Squid Web Proxy Cache 2.4 .STABLE4 Squid Web Proxy Cache 2.4 .STABLE2 Squid Web Proxy Cache 2.4 + Debian Linux 3.0 sparc + Debian Linux 3.0 s/390 + Debian Linux 3.0 ppc + Debian Linux 3.0 mipsel + Debian Linux 3.0 mips + Debian Linux 3.0 m68k + Debian Linux 3.0 ia-64 + Debian Linux 3.0 ia-32 + Debian Linux 3.0 hppa + Debian Linux 3.0 arm + Debian Linux 3.0 alpha + Debian Linux 3.0 Squid Web Proxy Cache 2.3 .STABLE5 Squid Web Proxy Cache 2.3 .STABLE4 Squid Web Proxy Cache 2.1 PATCH2 Squid Web Proxy Cache 2.0 PATCH2 Squid Web Proxy Cache 2.6.STABLE7 Squid Web Proxy Cache 2.6.STABLE6 Squid Web Proxy Cache 2.6.STABLE5 Squid Web Proxy Cache 2.6.STABLE4 Squid Web Proxy Cache 2.6.STABLE3 Squid Web Proxy Cache 2.6.STABLE2 Squid Web Proxy Cache 2.6.STABLE16 Squid Web Proxy Cache 2.6.STABLE15 Squid Web Proxy Cache 2.6.STABLE14 Squid Web Proxy Cache 2.6.STABLE13 Squid Web Proxy Cache 2.6.STABLE12 Squid Web Proxy Cache 2.6.STABLE1 Squid Web Proxy Cache 2.6 Squid Web Proxy Cache 2.5.STABLE14 Squid Web Proxy Cache 2.5.STABLE13 Squid Web Proxy Cache 2.5.STABLE12 Squid Web Proxy Cache 2.5.STABLE11 RedHat Fedora 8 0 RedHat Fedora 7 0 RedHat Enterprise Linux ES 4.6.z RedHat Enterprise Linux ES 4.5.z RedHat Enterprise Linux Desktop Workstation v. 5 client RedHat Enterprise Linux Desktop v.5 client RedHat Enterprise Linux AS 4.6.z RedHat Enterprise Linux AS 4.5.z RedHat Enterprise Linux WS 4 RedHat Enterprise Linux WS 3 RedHat Enterprise Linux WS 2.1 IA64 RedHat Enterprise Linux WS 2.1 RedHat Enterprise Linux v. 5 server RedHat Enterprise Linux ES 4 RedHat Enterprise Linux ES 3 RedHat Enterprise Linux ES 2.1 IA64 RedHat Enterprise Linux ES 2.1 RedHat Enterprise Linux AS 4 RedHat Enterprise Linux AS 3 RedHat Enterprise Linux AS 2.1 IA64 RedHat Enterprise Linux AS 2.1 RedHat Desktop 4.0 RedHat Desktop 3.0 RedHat Advanced Workstation for the Itanium Processor 2.1 IA64 RedHat Advanced Workstation for the Itanium Processor 2.1 MandrakeSoft Multi Network Firewall 2.0 MandrakeSoft Linux Mandrake 2008.0 x86_64 MandrakeSoft Linux Mandrake 2008.0 MandrakeSoft Linux Mandrake 2007.1 x86_64 MandrakeSoft Linux Mandrake 2007.1 MandrakeSoft Linux Mandrake 2007.0 x86_64 MandrakeSoft Linux Mandrake 2007.0 MandrakeSoft Corporate Server 4.0 x86_64 MandrakeSoft Corporate Server 3.0 x86_64 MandrakeSoft Corporate Server 3.0 MandrakeSoft Corporate Server 4.0 Squid Web Proxy Cache 2.6.STABLE7 Squid 11780.patch <a href=http://www.squid-cache.org/Versions/v2/2.6/changesets/11780.patch target=_blank>http://www.squid-cache.org/Versions/v2/2.6/changesets/11780.patch</a> Squid 2.6.STABLE17 <a href=http://www.squid-cache.org/Download/binaries.dyn target=_blank>http://www.squid-cache.org/Download/binaries.dyn</a> Squid Web Proxy Cache 2.5.STABLE12 Squid 2.6.STABLE17 <a href=http://www.squid-cache.org/Download/binaries.dyn target=_blank>http://www.squid-cache.org/Download/binaries.dyn</a> Squid Web Proxy Cache 2.6.STABLE14 Squid 11780.patch <a href=http://www.squid-cache.org/Versions/v2/2.6/changesets/11780.patch target=_blank>http://www.squid-cache.org/Versions/v2/2.6/changesets/11780.patch</a> Squid 2.6.STABLE17 <a href=http://www.squid-cache.org/Download/binaries.dyn target=_blank>http://www.squid-cache.org/Download/binaries.dyn</a> Squid Web Proxy Cache 2.6.STABLE6 Squid 11780.patch <a href=http://www.squid-cache.org/Versions/v2/2.6/changesets/11780.patch target=_blank>http://www.squid-cache.org/Versions/v2/2.6/changesets/11780.patch</a> Squid 2.6.STABLE17 <a href=http://www.squid-cache.org/Download/binaries.dyn target=_blank>http://www.squid-cache.org/Download/binaries.dyn</a> Squid Web Proxy Cache 2.6.STABLE5 Squid 11780.patch <a href=http://www.squid-cache.org/Versions/v2/2.6/changesets/11780.patch target=_blank>http://www.squid-cache.org/Versions/v2/2.6/changesets/11780.patch</a> Squid 2.6.STABLE17 <a href=http://www.squid-cache.org/Download/binaries.dyn target=_blank>http://www.squid-cache.org/Download/binaries.dyn</a> Squid Web Proxy Cache 2.5.STABLE11 Squid 2.6.STABLE17 <a href=http://www.squid-cache.org/Download/binaries.dyn target=_blank>http://www.squid-cache.org/Download/binaries.dyn</a> Squid Web Proxy Cache 2.5.STABLE13 Squid 2.6.STABLE17 <a href=http://www.squid-cache.org/Download/binaries.dyn target=_blank>http://www.squid-cache.org/Download/binaries.dyn</a> Squid Web Proxy Cache 2.6 Squid 11780.patch <a href=http://www.squid-cache.org/Versions/v2/2.6/changesets/11780.patch target=_blank>http://www.squid-cache.org/Versions/v2/2.6/changesets/11780.patch</a> Squid 2.6.STABLE17 <a href=http://www.squid-cache.org/Download/binaries.dyn target=_blank>http://www.squid-cache.org/Download/binaries.dyn</a> Squid Web Proxy Cache 2.6.STABLE1 Squid 11780.patch <a href=http://www.squid-cache.org/Versions/v2/2.6/changesets/11780.patch target=_blank>http://www.squid-cache.org/Versions/v2/2.6/changesets/11780.patch</a> Squid 2.6.STABLE17 <a href=http://www.squid-cache.org/Download/binaries.dyn target=_blank>http://www.squid-cache.org/Download/binaries.dyn</a> Squid Web Proxy Cache 2.5.STABLE14 Squid 2.6.STABLE17 <a href=http://www.squid-cache.org/Download/binaries.dyn target=_blank>http://www.squid-cache.org/Download/binaries.dyn</a> Squid Web Proxy Cache 2.6.STABLE4 Squid 11780.patch <a href=http://www.squid-cache.org/Versions/v2/2.6/changesets/11780.patch target=_blank>http://www.squid-cache.org/Versions/v2/2.6/changesets/11780.patch</a> Squid 2.6.STABLE17 <a href=http://www.squid-cache.org/Download/binaries.dyn target=_blank>http://www.squid-cache.org/Download/binaries.dyn</a> Squid Web Proxy Cache 2.6.STABLE3 Squid 11780.patch <a href=http://www.squid-cache.org/Versions/v2/2.6/changesets/11780.patch target=_blank>http://www.squid-cache.org/Versions/v2/2.6/changesets/11780.patch</a> Squid 2.6.STABLE17 <a href=http://www.squid-cache.org/Download/binaries.dyn target=_blank>http://www.squid-cache.org/Download/binaries.dyn</a> Squid Web Proxy Cache 2.6.STABLE16 Squid 11780.patch <a href=http://www.squid-cache.org/Versions/v2/2.6/changesets/11780.patch target=_blank>http://www.squid-cache.org/Versions/v2/2.6/changesets/11780.patch</a> Squid 2.6.STABLE17 <a href=http://www.squid-cache.org/Download/binaries.dyn target=_blank>http://www.squid-cache.org/Download/binaries.dyn</a> Squid Web Proxy Cache 2.6.STABLE12 Squid 11780.patch <a href=http://www.squid-cache.org/Versions/v2/2.6/changesets/11780.patch target=_blank>http://www.squid-cache.org/Versions/v2/2.6/changesets/11780.patch</a> Squid 2.6.STABLE17 <a href=http://www.squid-cache.org/Download/binaries.dyn target=_blank>http://www.squid-cache.org/Download/binaries.dyn</a> Squid Web Proxy Cache 2.6.STABLE15 Squid 11780.patch <a href=http://www.squid-cache.org/Versions/v2/2.6/changesets/11780.patch target=_blank>http://www.squid-cache.org/Versions/v2/2.6/changesets/11780.patch</a> Squid 2.6.STABLE17 <a href=http://www.squid-cache.org/Download/binaries.dyn target=_blank>http://www.squid-cache.org/Download/binaries.dyn</a> Squid Web Proxy Cache 2.6.STABLE2 Squid 11780.patch <a href=http://www.squid-cache.org/Versions/v2/2.6/changesets/11780.patch target=_blank>http://www.squid-cache.org/Versions/v2/2.6/changesets/11780.patch</a> Squid 2.6.STABLE17 <a href=http://www.squid-cache.org/Download/binaries.dyn target=_blank>http://www.squid-cache.org/Download/binaries.dyn</a> Squid Web Proxy Cache 2.6.STABLE13 Squid 11780.patch <a href=http://www.squid-cache.org/Versions/v2/2.6/changesets/11780.patch target=_blank>http://www.squid-cache.org/Versions/v2/2.6/changesets/11780.patch</a> Squid 2.6.STABLE17 <a href=http://www.squid-cache.org/Download/binaries.dyn target=_blank>http://www.squid-cache.org/Download/binaries.dyn</a> Squid Web Proxy Cache 2.0 PATCH2 Squid 2.6.STABLE17 <a href=http://www.squid-cache.org/Download/binaries.dyn target=_blank>http://www.squid-cache.org/Download/binaries.dyn</a> Squid Web Proxy Cache 2.1 PATCH2 Squid 2.6.STABLE17 <a href=http://www.squid-cache.org/Download/binaries.dyn target=_blank>http://www.squid-cache.org/Download/binaries.dyn</a> Squid Web Proxy Cache 2.3 .STABLE5 Squid 2.6.STABLE17 <a href=http://www.squid-cache.org/Download/binaries.dyn target=_blank>http://www.squid-cache.org/Download/binaries.dyn</a> Squid Web Proxy Cache 2.3 .STABLE4 Squid 2.6.STABLE17 <a href=http://www.squid-cache.org/Download/binaries.dyn target=_blank>http://www.squid-cache.org/Download/binaries.dyn</a> Squid Web Proxy Cache 2.4 .STABLE4 Squid 2.6.STABLE17 <a href=http://www.squid-cache.org/Download/binaries.dyn target=_blank>http://www.squid-cache.org/Download/binaries.dyn</a> Squid Web Proxy Cache 2.4 .STABLE7 Squid 2.6.STABLE17 <a href=http://www.squid-cache.org/Download/binaries.dyn target=_blank>http://www.squid-cache.org/Download/binaries.dyn</a> Squid Web Proxy Cache 2.4 .STABLE6 Squid 2.6.STABLE17 <a href=http://www.squid-cache.org/Download/binaries.dyn target=_blank>http://www.squid-cache.org/Download/binaries.dyn</a> Squid Web Proxy Cache 2.4 Squid 2.6.STABLE17 <a href=http://www.squid-cache.org/Download/binaries.dyn target=_blank>http://www.squid-cache.org/Download/binaries.dyn</a> Squid Web Proxy Cache 2.4 .STABLE2 Squid 2.6.STABLE17 <a href=http://www.squid-cache.org/Download/binaries.dyn target=_blank>http://www.squid-cache.org/Download/binaries.dyn</a> Squid Web Proxy Cache 2.5 .STABLE4 Squid 2.6.STABLE17 <a href=http://www.squid-cache.org/Download/binaries.dyn target=_blank>http://www.squid-cache.org/Download/binaries.dyn</a> Squid Web Proxy Cache 2.5 .STABLE10 Squid 2.6.STABLE17 <a href=http://www.squid-cache.org/Download/binaries.dyn target=_blank>http://www.squid-cache.org/Download/binaries.dyn</a> Squid Web Proxy Cache 2.5 .STABLE6 Squid 2.6.STABLE17 <a href=http://www.squid-cache.org/Download/binaries.dyn target=_blank>http://www.squid-cache.org/Download/binaries.dyn</a> Squid Web Proxy Cache 2.5 .STABLE3 Squid 2.6.STABLE17 <a href=http://www.squid-cache.org/Download/binaries.dyn target=_blank>http://www.squid-cache.org/Download/binaries.dyn</a> Squid Web Proxy Cache 2.5 .STABLE7 Squid 2.6.STABLE17 <a href=http://www.squid-cache.org/Download/binaries.dyn target=_blank>http://www.squid-cache.org/Download/binaries.dyn</a> Squid Web Proxy Cache 2.5 .STABLE10 Squid 2.6.STABLE17 <a href=http://www.squid-cache.org/Download/binaries.dyn target=_blank>http://www.squid-cache.org/Download/binaries.dyn</a> Squid Web Proxy Cache 2.5 .STABLE1 Squid 2.6.STABLE17 <a href=http://www.squid-cache.org/Download/binaries.dyn target=_blank>http://www.squid-cache.org/Download/binaries.dyn</a> Squid Web Proxy Cache 2.5 .STABLE5 Squid 2.6.STABLE17 <a href=http://www.squid-cache.org/Download/binaries.dyn target=_blank>http://www.squid-cache.org/Download/binaries.dyn</a> Squid Web Proxy Cache 2.5 .STABLE9 Squid 2.6.STABLE17 <a href=http://www.squid-cache.org/Download/binaries.dyn target=_blank>http://www.squid-cache.org/Download/binaries.dyn</a> Squid Web Proxy Cache 2.5 .STABLE8 Squid 2.6.STABLE17 <a href=http://www.squid-cache.org/Download/binaries.dyn target=_blank>http://www.squid-cache.org/Download/binaries.dyn</a> Squid Web Proxy Cache 3.0 PRE2 Squid 11211.patch <a href=http://www.squid-cache.org/Versions/v3/3.0/changesets/11211.patch target=_blank>http://www.squid-cache.org/Versions/v3/3.0/changesets/11211.patch</a> Squid Web Proxy Cache 3.0 PRE3 Squid 11211.patch <a href=http://www.squid-cache.org/Versions/v3/3.0/changesets/11211.patch target=_blank>http://www.squid-cache.org/Versions/v3/3.0/changesets/11211.patch</a> Squid Web Proxy Cache 3.0 PRE1 Squid 11211.patch <a href=http://www.squid-cache.org/Versions/v3/3.0/changesets/11211.patch target=_blank>http://www.squid-cache.org/Versions/v3/3.0/changesets/11211.patch</a> Squid Web Proxy Cache 3.0 Squid 11211.patch <a href=http://www.squid-cache.org/Versions/v3/3.0/changesets/11211.patch target=_blank>http://www.squid-cache.org/Versions/v3/3.0/changesets/11211.patch</a>