RHEL 2.1 / 3 : squid (RHSA-2004:591)

This script is Copyright (C) 2004-2014 Tenable Network Security, Inc.


Synopsis :

The remote Red Hat host is missing a security update.

Description :

An updated squid package that fixes a remote denial of service
vulnerability is now available.

Squid is a full-featured Web proxy cache.

iDEFENSE reported a flaw in the squid SNMP module. This flaw could
allow an attacker who has the ability to send arbitrary packets to the
SNMP port to restart the server, causing it to drop all open
connections. The Common Vulnerabilities and Exposures project
(cve.mitre.org) has assigned the name CVE-2004-0918 to this issue.

All users of squid should update to this erratum package, which
contains a backport of the security fix for this vulnerability.

See also :

https://www.redhat.com/security/data/cve/CVE-2004-0918.html
http://www.nessus.org/u?d34310cf
http://rhn.redhat.com/errata/RHSA-2004-591.html

Solution :

Update the affected squid package.

Risk factor :

Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:P)

Family: Red Hat Local Security Checks

Nessus Plugin ID: 15533 ()

Bugtraq ID:

CVE ID: CVE-2004-0918