Mandriva Linux Security Advisory : squid (MDVSA-2009:241-1)
Medium Nessus Plugin ID 43852
SynopsisThe remote Mandriva Linux host is missing one or more security updates.
DescriptionA vulnerability was discovered and corrected in squid :
The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allows remote attackers to cause a denial of service via a crafted auth header with certain comma delimiters that trigger an infinite loop of calls to the strcspn function (CVE-2009-2855).
This update provides a solution to this vulnerability.
Packages for 2008.0 are provided for Corporate Desktop 2008.0 customers.
SolutionUpdate the affected squid and / or squid-cachemgr packages.