thank You, Salvatore B. gonna try this today.
On Sun, Feb 24, 2013 at 2:51 AM, Salvatore Bonaccorso <car...@debian.org>wrote: > -----BEGIN PGP SIGNED MESSAGE----- > Hash: SHA1 > > - ------------------------------------------------------------------------- > Debian Security Advisory DSA-2630-1 secur...@debian.org > http://www.debian.org/security/ Salvatore Bonaccorso > February 24, 2013 http://www.debian.org/security/faq > - ------------------------------------------------------------------------- > > Package : squid3 > Vulnerability : denial of service > Problem type : remote > Debian-specific: no > CVE ID : CVE-2012-5643 CVE-2013-0189 > Debian Bug : 696187 > > Squid3, a fully featured Web proxy cache, is prone to a denial of > service attack due to memory consumption caused by memory leaks in > cachemgr.cgi: > > CVE-2012-5643 > > squid's cachemgr.cgi was vulnerable to excessive resource use. A > remote attacker could exploit this flaw to perform a denial of > service attack on the server and other hosted services. > > CVE-2013-0189 > > The original patch for CVE-2012-5643 was incomplete. A remote > attacker still could exploit this flaw to perform a denial of > service attack. > > For the stable distribution (squeeze), these problems have been fixed in > version 3.1.6-1.2+squeeze3. > > For the testing distribution (wheezy), these problems have been fixed in > version 3.1.20-2.1. > > For the unstable distribution (sid), these problems have been fixed in > version 3.1.20-2.1. > > We recommend that you upgrade your squid3 packages. > > Further information about Debian Security Advisories, how to apply > these updates to your system and frequently asked questions can be > found at: http://www.debian.org/security/ > > Mailing list: debian-security-annou...@lists.debian.org > > > -----BEGIN PGP SIGNATURE----- > Version: GnuPG v1.4.12 (GNU/Linux) > > iEYEARECAAYFAlEp8EUACgkQXm3vHE4uylqX2ACfVzLUYmz1xSlRJUcshNB/W6zv > KpIAoOVRw++ez+vx95H+dgN9vYG3he5p > =OrsC > -----END PGP SIGNATURE----- > > > -- > To UNSUBSCRIBE, email to debian-security-announce-requ...@lists.debian.org > with a subject of "unsubscribe". Trouble? Contact > listmas...@lists.debian.org > Archive: > http://lists.debian.org/20130224105143.GA6765@pisco.westfalen.local > >