Red Hat Bugzilla – Bug 439801
CVE-2008-1612 squid: regression in SQUID-2007:2 / CVE-2007-6239
Last modified: 2008-07-25 06:17:56 EDT
Squid security advisory SQUID-2007:2 was released on 2007-11-27 describing
potential denial of service (DoS) bug in squid proxy server:
The advisory was now updated to address problem introduced by the fix:
Following patch is need to allow shrinking squid Arrays to zero-sized arrays:
Issue was previously tracked using bug bug #410181.
This issue was introduced in the original fix for SQUID-2007_2. An attacker can
possibly cause squid child process to exit due to a failed assert. New child
process is spawned by the parent squid process to replace exited child. Child
process exit can easily interrupt current connections of other users.
Issue affects squid packages currently shipped in Red Hat Enterprise Linux 2.1,
3, 4, and 5.
This issue was addressed in:
Red Hat Enterprise Linux: