Bug 72581 - [Maintainer] www/squid: update to 2.5-STABLE7
Summary: [Maintainer] www/squid: update to 2.5-STABLE7
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: Normal Affects Only Me
Assignee: Sergei Kolobov
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2004-10-12 15:50 UTC by Thomas-Martin Seck
Modified: 2004-10-13 10:44 UTC (History)
1 user (show)

See Also:


Attachments
file.diff (9.03 KB, patch)
2004-10-12 15:50 UTC, Thomas-Martin Seck
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Thomas-Martin Seck 2004-10-12 15:50:31 UTC
- Update to 2.5-STABLE7; this release fixes a security issue regarding
  the SNMP module (security team CC'ed, see below for a proposed VuXML
  database entry)
- Remove a patch that is now part of the distribution
- Miscellaneuous small fixes:
  + in squid.sh, make stop_command poll for the squid processes' exit in
    the rcNG case too; this eliminates the need to do this in restart_command
  + make the information regarding rcNG'ness in pkg-install easier to read
  + install unstripped binaries if WITH_SQUID_STACKTRACES is defined

Note to committer:
please 'cvs rm' files/patch-configure

Proposed VuXML database entry regarding the SNMP issue:
<topic>Denial of Service Issue in squid SNMP module</topic>
<affects>
	<package>
		<name>squid</name>
	<range><lt>2.5.7</lt></range>
	<package>
</affects>
<description>
	<body xmlns="http://www.w3.org/1999/xhtml">
	<p>If a certain malformed SNMP request is received squid restarts
	with a Segmentation Fault error.</p>
	<p>This only affects squid installations where SNMP is explicitly
	enabled via &quot;make config&quot;. As a workaround, SNMP can be
	disabled by defining &quot;snmp_port 0&quot; in squid.conf.</p>
	</body>
</description>
<references>
	<cvename>CAN-2004-0918</cvename>
	<url>http://www.squid-cache.org/Versions/v2/2.5/bugs/#squid-2.5.STABLE6-SNMP_core_dump</url>
</references>
<dates>
	<discovery>2004-09-29</discovery>
</dates>

Fix: Apply this patch:
Comment 1 Sergei Kolobov freebsd_committer freebsd_triage 2004-10-12 17:50:03 UTC
Responsible Changed
From-To: freebsd-ports-bugs->sergei

Grab.
Comment 2 Sergei Kolobov freebsd_committer freebsd_triage 2004-10-13 10:44:07 UTC
State Changed
From-To: open->closed

Committed, thanks!