]> git.ipfire.org Git - ipfire-2.x.git/commit
squid: Apply fix for Squid Advisory SQUID-2015:2
authorMichael Tremer <michael.tremer@ipfire.org>
Thu, 9 Jul 2015 10:29:37 +0000 (12:29 +0200)
committerMichael Tremer <michael.tremer@ipfire.org>
Thu, 9 Jul 2015 11:10:38 +0000 (13:10 +0200)
commitd6c40f585dfe3f346651d53fb1bebaf0dae51a4f
tree9d8703197af474a78623bcd5d8e9621b9a123377
parentc50d4f54b6090962f0b7f1081711a0f8185cf268
squid: Apply fix for Squid Advisory SQUID-2015:2

Squid configured with cache_peer and operating on explicit proxy
traffic does not correctly handle CONNECT method peer responses.

The bug is important because it allows remote clients to bypass
security in an explicit gateway proxy.

However, the bug is exploitable only if you have configured
cache_peer to receive CONNECT requests.

  http://www.squid-cache.org/Advisories/SQUID-2015_2.txt

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
config/rootfiles/core/92/filelists/squid [new symlink]
lfs/squid
src/patches/squid-3.4-13225.patch [new file with mode: 0644]