Submitted by JamesStrandboge on Thu, 2009-02-26 12:26
Referenced CVEs:
CVE-2009-0478
Description:
===========================================================
Ubuntu Security Notice USN-724-1 February 25, 2009
squid vulnerability
CVE-2009-0478
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 8.10
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 8.10:
squid 2.7.STABLE3-1ubuntu2.1
In general, a standard system upgrade is sufficient to effect the
necessary changes.
Details follow:
Joshua Morin, Mikko Varpiola and Jukka Taimisto discovered that Squid did
not properly validate the HTTP version when processing requests. A remote
attacker could exploit this to cause a denial of service (assertion failure).


