Debian DSA-1991-1 : squid/squid3 - denial of service

medium Nessus Plugin ID 44855

Language:

Synopsis

The remote Debian host is missing a security-related update.

Description

Two denial of service vulnerabilities have been discovered in squid and squid3, a web proxy. The Common Vulnerabilities and Exposures project identifies the following problems :

- CVE-2009-2855 Bastian Blank discovered that it is possible to cause a denial of service via a crafted auth header with certain comma delimiters.

- CVE-2010-0308 Tomas Hoger discovered that it is possible to cause a denial of service via invalid DNS header-only packets.

Solution

Upgrade the squid/squid3 packages.

For the stable distribution (lenny), these problems have been fixed in version 2.7.STABLE3-4.1lenny1 of the squid package and version 3.0.STABLE8-3+lenny3 of the squid3 package.

For the oldstable distribution (etch), these problems have been fixed in version 2.6.5-6etch5 of the squid package and version 3.0.PRE5-5+etch2 of the squid3 package.

See Also

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=534982

https://security-tracker.debian.org/tracker/CVE-2009-2855

https://security-tracker.debian.org/tracker/CVE-2010-0308

https://www.debian.org/security/2010/dsa-1991

Plugin Details

Severity: Medium

ID: 44855

File Name: debian_DSA-1991.nasl

Version: 1.10

Type: local

Agent: unix

Published: 2/24/2010

Updated: 1/4/2021

Supported Sensors: Agentless Assessment, Continuous Assessment, Frictionless Assessment Agent, Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Low

Score: 3.6

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 4.1

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Information

CPE: p-cpe:/a:debian:debian_linux:squid3, cpe:/o:debian:debian_linux:4.0, cpe:/o:debian:debian_linux:5.0

Required KB Items: Host/local_checks_enabled, Host/Debian/release, Host/Debian/dpkg-l

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2/4/2010

Reference Information

CVE: CVE-2009-2855, CVE-2010-0308

BID: 36091, 37522

CWE: 20

DSA: 1991