Debian Security Advisory
DSA-3139-1 squid -- security update
- Date Reported:
- 25 Jan 2015
- Affected Packages:
- squid
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 776194.
In Mitre's CVE dictionary: CVE-2014-3609. - More information:
-
Matthew Daley discovered that squid, a web proxy cache, does not properly perform input validation when parsing requests. A remote attacker could use this flaw to mount a denial of service attack, by sending specially crafted Range requests.
For the stable distribution (wheezy), this problem has been fixed in version 2.7.STABLE9-4.1+deb7u1.
We recommend that you upgrade your squid packages.