Family: Mandrake Local Security Checks --> Category: infos
MDKSA-2001:066: squid Vulnerability Scan
Vulnerability Scan Summary
Check for the version of the squid package
Detailed Explanation for this Vulnerability Test
The remote host is missing the patch for the advisory MDKSA-2001:066 (squid).
The Squid proxy server has a serious security flaw in versions 2.3.STABLE2
through 2.3.STABLE4. This problem surfaces when Squid is used in httpd_accel
mode. If you configure http_accel_with_proxy off then any request to Squid is
allowed. Malicious users may use your proxy to portscan remote systems, forge
email, and other activities.
Solution : http://wwwnew.mandriva.com/security/advisories?name=MDKSA-2001:066
Threat Level: High
Click HERE for more information and discussions on this network vulnerability scan.