]> git.ipfire.org Git - people/trikolon/ipfire-2.x.git/commit
squid: Apply fix for Squid Advisory SQUID-2015:2
authorMichael Tremer <michael.tremer@ipfire.org>
Thu, 9 Jul 2015 10:29:37 +0000 (12:29 +0200)
committerMichael Tremer <michael.tremer@ipfire.org>
Thu, 9 Jul 2015 10:31:04 +0000 (12:31 +0200)
commitd1b7736a280f41f847dd879d5cbf8bb233101684
treeddeb818f5bcbe33277e22eeee19c5ad1818a81ce
parent373c622aa65b113e945e5570383c8d8eb2702c19
squid: Apply fix for Squid Advisory SQUID-2015:2

Squid configured with cache_peer and operating on explicit proxy
traffic does not correctly handle CONNECT method peer responses.

The bug is important because it allows remote clients to bypass
security in an explicit gateway proxy.

However, the bug is exploitable only if you have configured
cache_peer to receive CONNECT requests.

  http://www.squid-cache.org/Advisories/SQUID-2015_2.txt

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
config/rootfiles/core/92/filelists/squid [new symlink]
lfs/squid
src/patches/squid-3.4-13225.patch [new file with mode: 0644]