Mandriva Linux Security Advisory : squid (MDVSA-2010:187)
Medium Nessus Plugin ID 49654
SynopsisThe remote Mandriva Linux host is missing one or more security updates.
DescriptionA vulnerability has been found and corrected in squid :
The string-comparison functions in String.cci in Squid 3.x before 3.1.8 and 3.2.x before 22.214.171.124 allow remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted request (CVE-2010-3072).
Packages for 2008.0 and 2009.0 are provided as of the Extended Maintenance Program. Please visit this link to learn more:
The updated packages have been patched to correct this issue.
SolutionUpdate the affected squid and / or squid-cachemgr packages.