Pop-Up Thingie

>>> Magnum BBS <<<
  • Home
  • Forum
  • Files
  • Log in

  1. Forum
  2. Usenet
  3. LINUX.DEBIAN.ANNOUNCE.SEC
  • [SECURITY] [DSA-1646-1] New squid packages fix array bounds check (1/2)

    From Devin Carraway@1:229/2 to All on Tue Oct 7 08:20:07 2008
    From: [email protected]

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    - ------------------------------------------------------------------------ Debian Security Advisory DSA-1646-1 [email protected] http://www.debian.org/security/ Devin Carraway October 07, 2008 http://www.debian.org/security/faq
    - ------------------------------------------------------------------------

    Package : squid
    Vulnerability : array bounds check
    Problem type : remote
    Debian-specific: no
    CVE Id(s) : CVE-2008-1612

    A weakness has been discovered in squid, a caching proxy server. The
    flaw was introduced upstream in response to CVE-2007-6239, and
    announced by Debian in DSA-1482-1. The flaw involves an
    over-aggressive bounds check on an array resize, and could be
    exploited by an authorized client to induce a denial of service
    condition against squid.

    For the stable distribution (etch), these problems have been fixed in
    version 2.6.5-6etch2.

    We recommend that you upgrade your squid packages.


    Upgrade instructions
    - --------------------

    wget url
    will fetch the file for you
    dpkg -i file.deb
    will install the referenced file.

    If you are using the apt-get package manager, use the line for
    sources.list as given below:

    apt-get update
    will update the internal database
    apt-get upgrade
    will install corrected packages

    You may use an automated update by adding the resources from the
    footer to the proper configuration.


    Debian GNU/Linux 4.0 alias etch
    - -------------------------------

    Debian (stable)
    - ---------------

    Stable updates are available for alpha, amd64, arm, hppa, i386, ia64, mips, mipsel, powerpc, s390 and sparc.

    Source archives:

    http://security.debian.org/pool/updates/main/s/squid/squid_2.6.5.orig.tar.gz
    Size/MD5 checksum: 1636886 26cc918028340dc8ceb9c0c4b988d717
    http://security.debian.org/pool/updates/main/s/squid/squid_2.6.5-6etch2.diff.gz
    Size/MD5 checksum: 273482 a50f26f9efdb5a4cecb924079a7acfb9
    http://security.debian.org/pool/updates/main/s/squid/squid_2.6.5-6etch2.dsc
    Size/MD5 checksum: 669 b1726dce2c7eea1e010906ea38bf072c

    Architecture independent packages:

    http://security.debian.org/pool/updates/main/s/squid/squid-common_2.6.5-6etch2_all.deb
    Size/MD5 checksum: 437244 8bc777de8a4c48c8bf97b549f623c3b4

    alpha architecture (DEC Alpha)

    http://security.debian.org/pool/updates/main/s/squid/squidclient_2.6.5-6etch2_alpha.deb
    Size/MD5 checksum: 88358 85c2aa241e702ccbf2b628adeacb31ca
    http://security.debian.org/pool/updates/main/s/squid/squid_2.6.5-6etch2_alpha.deb
    Size/MD5 checksum: 793566 ffdb43d648ad1bf20bf7abe02bdf02c3
    http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.6.5-6etch2_alpha.deb
    Size/MD5 checksum: 119714 dce5baad9332f9e854f193770798025c

    amd64 architecture (AMD x86_64 (AMD64))

    http://security.debian.org/pool/updates/main/s/squid/squidclient_2.6.5-6etch2_amd64.deb
    Size/MD5 checksum: 86296 6f3e9c710fd34f6e6dc73f59dd08305f
    http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.6.5-6etch2_amd64.deb
    Size/MD5 checksum: 116682 a5cd8cc313c0ac1b029465ea20e4f545
    http://security.debian.org/pool/updates/main/s/squid/squid_2.6.5-6etch2_amd64.deb
    Size/MD5 checksum: 708968 e8742c13712128d60a771644ebba83c4

    arm architecture (ARM)

    http://security.debian.org/pool/updates/main/s/squid/squidclient_2.6.5-6etch2_arm.deb
    Size/MD5 checksum: 86138 3dacde2e043c0569b3d91967cbd8a12a
    http://security.debian.org/pool/updates/main/s/squid/squid_2.6.5-6etch2_arm.deb
    Size/MD5 checksum: 676532 82a513ebd7efa71b7c4d433c11a92e21
    http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.6.5-6etch2_arm.deb
    Size/MD5 checksum: 116058 a1f1c3e60860d99abc8a357756b8286c

    hppa architecture (HP PA RISC)

    http://security.debian.org/pool/updates/main/s/squid/squid_2.6.5-6etch2_hppa.deb
    Size/MD5 checksum: 748436 f367be1a2654ba16ea5ffb8cd9402d0d
    http://security.debian.org/pool/updates/main/s/squid/squidclient_2.6.5-6etch2_hppa.deb
    Size/MD5 checksum: 88006 bb51d372ee4bfefc50ad14dd80a3fd1e
    http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.6.5-6etch2_hppa.deb
    Size/MD5 checksum: 118664 73d47d6e71b0c587b5ee47c050e73fed

    i386 architecture (Intel ia32)

    http://security.debian.org/pool/updates/main/s/squid/squid_2.6.5-6etch2_i386.deb
    Size/MD5 checksum: 655102 974ebf7aa186c3bcad04db331eb1f9ef
    http://security.debian.org/pool/updates/main/s/squid/squidclient_2.6.5-6etch2_i386.deb
    Size/MD5 checksum: 86032 8b76b6bef4d98138f0257e2facf390e3
    http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.6.5-6etch2_i386.deb
    Size/MD5 checksum: 116484 1bf5155048c9f99ad0550a948dc7ec54

    ia64 architecture (Intel ia64)

    http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.6.5-6etch2_ia64.deb
    Size/MD5 checksum: 124294 46d7deb973420ec5e1fcf0d285b9c0fd
    http://security.debian.org/pool/updates/main/s/squid/squid_2.6.5-6etch2_ia64.deb
    Size/MD5 checksum: 1067214 28910fa078f1877aa9cc481e2601978f
    http://security.debian.org/pool/updates/main/s/squid/squidclient_2.6.5-6etch2_ia64.deb
    Size/MD5 checksum: 91458 9aceade803ca62f2ea942816d0e58a09

    mips architecture (MIPS (Big Endian))

    http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.6.5-6etch2_mips.deb
    Size/MD5 checksum: 118250 86ad63f2ec01a03938a831f60c31a376
    http://security.debian.org/pool/updates/main/s/squid/squidclient_2.6.5-6etch2_mips.deb
    Size/MD5 checksum: 87452 8e70de43fecdd3600edf9717ddc3654e
    http://security.debian.org/pool/updates/main/s/squid/squid_2.6.5-6etch2_mips.deb
    Size/MD5 checksum: 739976 606bc3bf5b060bd90ac2527e0eaf8428

    mipsel architecture (MIPS (Little Endian))

    http://security.debian.org/pool/updates/main/s/squid/squid_2.6.5-6etch2_mipsel.deb
    Size/MD5 checksum: 747420 47dfe6d5a3f07c07de007b3ffdbf040b
    http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.6.5-6etch2_mipsel.deb
    Size/MD5 checksum: 117306 9142ed1e467e20063cc7dedbcc364738
    http://security.debian.org/pool/updates/main/s/squid/squidclient_2.6.5-6etch2_mipsel.deb
    Size/MD5 checksum: 87384 4564cc7b0bb576fd5751b4571fb136f3

    powerpc architecture (PowerPC)

    http://security.debian.org/pool/updates/main/s/squid/squid-cgi_2.6.5-6etch2_powerpc.deb
    Size/MD5 checksum: 116466 b658e55a0d48925469d8bb4da653a354

    [continued in next message]

    --- SoupGate-Win32 v1.05
    * Origin: you cannot sedate... all the things you hate (1:229/2)
  • Who's Online

  • Recent Visitors

    • Centurion
      Mon Jun 8 21:33:11 2026
      from Berea, Ohio via Telnet
    • Bob Worm
      Mon Jun 8 20:15:00 2026
      from Wales, Uk via Telnet
    • Bob Worm
      Mon Jun 8 16:33:22 2026
      from Wales, Uk via Telnet
    • Bob Worm
      Mon Jun 8 14:11:46 2026
      from Wales, Uk via Telnet
    • Krenn
      Mon Jun 8 11:22:02 2026
      from Sydney, Nsw via Telnet
    • Bob Worm
      Mon Jun 8 08:26:26 2026
      from Wales, Uk via Telnet
    • Spearb0y
      Mon Jun 8 06:51:02 2026
      from Massachusetts via SSH
    • Krenn
      Mon Jun 8 05:45:38 2026
      from Sydney, Nsw via Telnet
  • System Info

    Sysop: Keyop
    Location: Huddersfield, West Yorkshire, UK
    Users: 715
    Nodes: 16 (2 / 14)
    Uptime: 29:43:11
    Calls: 12,108
    Calls today: 8
    Files: 15,006
    Messages: 6,518,245

© >>> Magnum BBS <<<, 2026