[Secure-testing-team] Bug#572554: CVE-2010-0639: HTCP DoS

Moritz Muehlenhoff jmm at debian.org
Thu Mar 4 20:51:43 UTC 2010


Package: squid3
Version: 3.0.STABLE19-1
Severity: important
Tags: security

http://www.squid-cache.org/Advisories/SQUID-2010_2.txt

Since this a non-default issues with limited local impact I don't
think this needs to be fixed in a DSA. Still, you could fix this
through a stable point update.

Cheers,
        Moritz

-- System Information:
Debian Release: squeeze/sid
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: i386 (i686)

Kernel: Linux 2.6.32-2-686 (SMP w/1 CPU core)
Locale: LANG=C, LC_CTYPE=de_DE.ISO-8859-15 at euro (charmap=ISO-8859-15)
Shell: /bin/sh linked to /bin/bash

Versions of packages squid3 depends on:
ii  adduser                   3.112          add and remove users and groups
ii  libc6                     2.10.2-5       Embedded GNU C Library: Shared lib
pn  libdb4.6                  <none>         (no description available)
ii  libgcc1                   1:4.4.3-2      GCC support library
ii  libldap-2.4-2             2.4.17-2.1     OpenLDAP libraries
ii  libpam0g                  1.1.1-2        Pluggable Authentication Modules l
ii  libsasl2-2                2.1.23.dfsg1-5 Cyrus SASL - authentication abstra
ii  libstdc++6                4.4.3-2        The GNU Standard C++ Library v3
ii  logrotate                 3.7.8-4        Log rotation utility
ii  lsb-base                  3.2-23         Linux Standard Base 3.2 init scrip
ii  netbase                   4.40           Basic TCP/IP networking system
pn  squid3-common             <none>         (no description available)

squid3 recommends no packages.

Versions of packages squid3 suggests:
pn  resolvconf                    <none>     (no description available)
pn  smbclient                     <none>     (no description available)
pn  squid3-cgi                    <none>     (no description available)
pn  squidclient                   <none>     (no description available)





More information about the Secure-testing-team mailing list