ELSA-2013-0505

ELSA-2013-0505 - squid security and bug fix update

Type:SECURITY
Severity:MODERATE
Release Date:2013-02-22

Description


[7:3.1.10-16]
- Resolves: #888198 - CVE-2012-5643: improved upstream patch

[7:3.1.10-15]
- Reverts: #861062 - Squid delays on FQDNs that don't contains AAAA record

[7:3.1.10-14]
- Resolves: #888198 - CVE-2012-5643: patch

[7:3.1.10-13]
- Resolves: #888198 - CVE-2012-5643: DoS (excessive resource consumption)

[7:3.1.10-12]
- Resolves #861062 - add configure directive --enable-internal-dns

[7:3.1.10-11 ]
- Resolves #861062 - Squid delays on FQDNs that don't contains AAAA record

[7:3.1.10-10]
- Resolves #798090 - Client timeout uses server-side 'read_timeout'
- Resolves #833086 - Private md5 hash function does not comply FIPS
- Resolves #782732 - Squid crashes by segfault when it reboots
- Resolves #797571 - Squid userid is not added to wbpriv group
- Disable strict-error-checking on account of squid-fips.patch


Related CVEs


CVE-2012-5643

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 6 (i386) squid-3.1.10-16.el6.src.rpmf9e0efbc5ae6002b78441a49feaa6e86ELBA-2017-0753
squid-3.1.10-16.el6.i686.rpm48befde7102139d03513072d5cf28febELBA-2017-0753
Oracle Linux 6 (x86_64) squid-3.1.10-16.el6.src.rpmf9e0efbc5ae6002b78441a49feaa6e86ELBA-2017-0753
squid-3.1.10-16.el6.x86_64.rpmb1e47baf1664cc84078ef99a1f652aaaELBA-2017-0753



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete